4.5.15 Ensure nonlocsrcroute is disabled

Information

The nonlocsrcroute parameter determines whether the system allows source routed packets to be addressed to hosts outside of the LAN.

The nonlocsrcroute parameter will be set to 0 This means that the system will not allow source routed packets to be addressed to hosts outside of the LAN. By default, when this is enabled the system is susceptible to source routing attacks.

Solution

In /etc/tunables/nextboot add the nonlocsrcroute entry:

no -p -o nonlocsrcroute=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 4cb9591183fb0899f2c411257637d3b4c0aa6797cb02cf397e0ca80f431d5330