RHEL-07-040740 - The Red Hat Enterprise Linux operating system must not be performing packet forwarding unless the system is a router.

Information

Routing protocol daemons are typically used on routers to exchange network topology information with other routers. If this software is used when not required, system network information may be unnecessarily transmitted across the network.

Solution

Set the system to the required kernel parameter by adding the following line to '/etc/sysctl.conf' or a configuration file in the /etc/sysctl.d/ directory (or modify the line to have the required value):

net.ipv4.ip_forward = 0

Issue the following command to make the changes take effect:

# sysctl --system

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R15_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-204625r991589_rule, STIG-ID|RHEL-07-040740, STIG-Legacy|SV-86933, STIG-Legacy|V-72309, Vuln-ID|V-204625

Plugin: Unix

Control ID: f76ccdbd022abb0501950163e3e33e4db7a6c180acd4ebc2593ccf1da3411bca