GEN005560 - The system must be configured with a default gateway for IPv4 if the system uses IPv4, unless the system is a router.

Information

If a system has no default gateway defined, the system is at increased risk of man-in-the-middle, monitoring, and Denial of Service attacks.

Solution

Create or edit /etc/defaultrouter to contain the default gateway address.

Procedure (for a default gateway of 192.168.3.1):
# echo '192.168.3.1' > /etc/defaultrouter

Restart the system for the setting to take effect.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-227909r603266_rule, STIG-ID|GEN005560, STIG-Legacy|SV-30079, STIG-Legacy|V-4397, Vuln-ID|V-227909

Plugin: Unix

Control ID: 04639dd5aeefb5b41e8d3366e41ec6c5759b2197a673c9712c5e631c75b4cb52