SOL-11.1-050040 - The system must not respond to ICMP broadcast netmask requests.

Information

By determining the netmasks of various computers in your network, an attacker can better map your subnet structure and infer trust relationships.

Solution

The Network Management profile is required.

Disable responses to address mask broadcast.

# pfexec ipadm set-prop -p _respond_to_address_mask_broadcast=0 ip

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-216371r959010_rule, STIG-ID|SOL-11.1-050040, STIG-Legacy|SV-61049, STIG-Legacy|V-48177, Vuln-ID|V-216371

Plugin: Unix

Control ID: 6410c99d41dbd93501b51203e16ac7f7b1c1a9ec70278693681bb3259f708fb5