SOL-11.1-050060 - The system must not respond to multicast echo requests.

Information

Multicast echo requests can be useful for reconnaissance of systems and for denial of service attacks.

Solution

The Network Management profile is required.

Disable respond to echo multi-cast for IPv4 and IPv6.

# pfexec ipadm set-prop -p _respond_to_echo_multicast=0 ipv4
# pfexec ipadm set-prop -p _respond_to_echo_multicast=0 ipv6

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-216373r959010_rule, STIG-ID|SOL-11.1-050060, STIG-Legacy|SV-61057, STIG-Legacy|V-48185, Vuln-ID|V-216373

Plugin: Unix

Control ID: 3a36ee9ce23d52c87c7026a33d4a458775b490eccc22fb177023e8c3c5b7aa77