ICMP: Do not return unreachable messages

Information

Prevent routers from responding with unreachable notifications can be implemented at router and service interface. For interfaces such as IES or VPRN, the service interface is used to configure the ICMP parameters. ICMP mask replies are commonly used for network mapping and information gathering. These messages do not provide any legitimately required services so should be disabled. Redirects and unreachables can either be turned off or rate-limited.

Solution

Run the following command on the device to disable ICMP options for interfaces that do not require it: configure router if <interface-id> icmp no <option>

See Also

https://infoproducts.alcatel-lucent.com/aces/cgi-bin/dbaccessfilename.cgi/9305050101_V1_SR-OS Security Best Practices v2.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Alcatel

Control ID: 0690922d4e904ea3d6697ce3d0c59c7d16103bd2f7f64a68ea8bf542421f7b02