1.12 CISC-RT-000190

Information

The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) redirect messages disabled on all external interfaces.

Group ID: V-221085
Rule ID: SV-221085r999694

The ICMP supports IP traffic by relaying information about paths, routes, and network conditions. Switches automatically send ICMP messages under a wide variety of conditions. Redirect ICMP messages are commonly used by attackers for network mapping and diagnosis.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Disable ICMP redirects on all external interfaces as shown in the example below:

SW1(config)# int e2/7
SW1(config-if)# no ip redirects

See Also

https://workbench.cisecurity.org/benchmarks/26426

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-5, 800-53|SC-7, 800-53|SC-7(5), CSCv7|12.4, Rule-ID|SV-221085r999694_rule, STIG-ID|CISC-RT-000190, Vuln-ID|V-221085

Plugin: Cisco

Control ID: 9d1b6e63d846fb8fe0e47ce79f2e44d95c6a82def2d8939df5363b9a8e5a78c0