Network Security - Disable ICMP Source Quench - no-source-quench

Information

ICMP source quench (ICMP Type 4) is a congestion control technique used by receiving devices to tell the sending the device to reduce the amount of traffic it is sending. Ideally it is used to control the flow of traffic to reduce retransmissions and dropped packets but in reality it can be used in a blind throughput reduction attack.

Routers shouldn't process source quench messages (RFC1812) and RFC6633 formally deprecates its handing in other transport protocols. There are more effective methods of implementing congestion control and ICMP source quench has been found to be largely ineffective and for those reasons source quench should be disabled.

Solution

Configure the system to disable ICMP source quench.

user@host# edit system internet-options
user@host# set no-source-quench

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Juniper

Control ID: b83fbcd5170c44aaaca0cc22eeffc1f4a9d7ff92c8b23358644470f06b49d3c1