Network Security - Globally disable ICMP redirects

Information

ICMP redirects should be the exception and not the rule. A properly designed network should not rely on ICMP to function normally.

The threat posed by ICMP redirects is that a DoS attack could be launched that forces a router to respond to thousands of suboptimally routed packets per second, consuming all valuable resources.

Solution

Configure system no redirects for ICMP.

user@host# edit system
user@host# set no-redirects

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7

Plugin: Juniper

Control ID: 7c5897373b01142c42d389f04706cda96c667788a3d01f094b97c6c29500bc5d