GEN003619 - The system must not be configured for network bridging.

Information

Some systems have the ability to bridge or switch frames (link-layer forwarding) between multiple interfaces. This can be useful in a variety of situations but, if enabled when not needed, has the potential to bypass network partitioning and security.

Solution

Configure the system to not use bridging.
# rmmod bridge
Edit /etc/modprobe.conf and add a line such as 'install bridge /bin/false' to prevent the loading of the bridge module.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-001551, CSCv6|9.1, Group-ID|V-22421, Rule-ID|SV-37639r1_rule, STIG-ID|GEN003619

Plugin: Unix

Control ID: 30da30b37a7c899568d2257b59b336ece76e618a312be0046239fd790ed441ea