40740 - The system must not be performing packet forwarding unless the system is a router - config

Information

Routing protocol daemons are typically used on routers to exchange network topology information with other routers. If this software is used when not required, system network information may be unnecessarily transmitted across the network.

Solution

Set the system to the required kernel parameter by adding the following line to '/etc/sysctl.conf' or a configuration file in the /etc/sysctl.d/ directory (or modify the line to have the required value):

net.ipv4.ip_forward = 0

Issue the following command to make the changes take effect:

# sysctl --system

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CAT|II, CCI|CCI-000366, CSCv6|9.2

Plugin: Unix

Control ID: 9a957619bd03c6d46c63fa600664a60540c1f2f57b00f631ece16a52d6bf87e2