WN12-SO-000037 - IPv6 source routing must be configured to the highest protection level.

Information

Configuring the system to disable IPv6 source routing protects against spoofing.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' to 'Highest protection, source routing is completely disabled'.

(See 'Updating the Windows Security Options File' in the STIG Overview document if MSS settings are not visible in the system's policy tools.)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-225479r569185_rule, STIG-ID|WN12-SO-000037, STIG-Legacy|SV-53180, STIG-Legacy|V-21955, Vuln-ID|V-225479

Plugin: Windows

Control ID: 7c3621afeacdf63e5005a7c4ca057cb80e0568331356f4ce48440af5d58d5b9c