GEN003611 - The system must log martian packets - 'net.ipv4.conf.default.log_martians'

Information

Martian packets are packets containing addresses known by the system to be invalid. Logging these messages allows the SA to identify misconfigurations or attacks in progress.

Solution

Configure the system to log martian packets.
Edit /etc/sysctl.conf and add a setting for 'net.ipv4.conf.all.log_martians=1' and 'net.ipv4.conf.default.log_martians=1'.

Reload the sysctls.
Procedure:
# sysctl -p

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2d., CAT|III, CCE|CCE-4320-8, CCI|CCI-000126, Group-ID|V-22418, Rule-ID|SV-37630r1_rule, STIG-ID|GEN003611, Vuln-ID|V-22418

Plugin: Unix

Control ID: b113ff502bf336d88bcd73600403fb93d6dfa4bca193e3f378b66771b6efc25d