GEN003602 - The system must not process ICMP timestamp requests.

Information

The processing of Internet Control Message Protocol (ICMP) timestamp requests increases the attack surface of the system.

Solution

Disable ICMP timestamp responses on the system.
# ndd -set /dev/ip ip_respond_to_timestamp 0
Also add this command to a system startup script.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-227795r603266_rule, STIG-ID|GEN003602, STIG-Legacy|SV-26621, STIG-Legacy|V-22409, Vuln-ID|V-227795

Plugin: Unix

Control ID: f47a85398c0fe2615eb0c1dca720983d59e8162b0f6f217d95d5d3548e6bffaf