SonicWALL - Detection Prevention - ICMP packets

Information

SonicWALL - Detection Prevention - Never generate ICMP Time-Exceeded packets. The SonicWALL appliance generates Time-Exceeded packets to report when it has dropped a packet because its TTL value has decreased to zero. Select this option if you do not want the SonicWALL appliance to generate these reporting packets.

Solution

Navigate to Firewall Settings->Advanced->Detection Prevention and check off 'Never generate ICMP Time-Exceeded packets' and 'Decrement IP TTL for forwarded traffic'.

Item Details

Audit Name: TNS SonicWALL v5.9

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7

Plugin: SonicWALL

Control ID: 38e1b12276cafc13169a59374935e485f56d3df17b7a398c2023795697b8eb9b