4.630 - The system must not respond to Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) echoes sent to a broadcast address - config

Information

Responding to broadcast (ICMP) echoes facilitates network mapping and provides a vector for amplification attacks.

Solution

Set the system to the required kernel parameter by adding the following line to '/etc/sysctl.conf' or a configuration file in the /etc/sysctl.d/ directory (or modify the line to have the required value):

net.ipv4.icmp_echo_ignore_broadcasts = 1

Issue the following command to make the changes take effect:

# sysctl --system

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CAT|II, CCI|CCI-000366, CSCv6|9.2

Plugin: Unix

Control ID: 7553501117b3d8d5a3daee9c4460d41971f8fcdfb4a1b1914235733374ee48ea