4.5.11 Ensure ipsrcrouterecv is disabled

Information

The ipsrcrouterecv parameter determines whether the system accepts source routed packets.

The ipsrcrouterecv parameter will be set to 0 This means that the system will not accept source routed packets. By default, when this is enabled the system is susceptible to source routing attacks.

Solution

In /etc/tunables/nextboot add the ipsrcrouterecv entry:

no -p -o ipsrcrouterecv=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 771c9ae21263709e73a4f2898e6aee27868633baf6e6a878e417827800978184