SOL-11.1-050070 - The system must ignore ICMP redirect messages.

Information

Ignoring ICMP redirect messages reduces the likelihood of denial of service attacks.

Solution

The Network Management profile is required.

Disable ignore redirects for IPv4 and IPv6.

# pfexec ipadm set-prop -p _ignore_redirect=1 ipv4
# pfexec ipadm set-prop -p _ignore_redirect=1 ipv6

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-216137r959010_rule, STIG-ID|SOL-11.1-050070, STIG-Legacy|SV-61061, STIG-Legacy|V-48189, Vuln-ID|V-216137

Plugin: Unix

Control ID: 869bbb32ff7c2df4620ae3b916389f226c98070533a60ece4e9022ad0606b4e8