WN12-SO-000038 - The system must be configured to prevent IP source routing.

Information

Configuring the system to disable IP source routing protects against spoofing.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' to 'Highest protection, source routing is completely disabled'.

(See 'Updating the Windows Security Options File' in the STIG Overview document if MSS settings are not visible in the system's policy tools.)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-225480r569185_rule, STIG-ID|WN12-SO-000038, STIG-Legacy|SV-52924, STIG-Legacy|V-4110, Vuln-ID|V-225480

Plugin: Windows

Control ID: 82e32f99c6c6733cda57cce51c36108ccaa5df696072b7084c3794ff7898e9f8