4.5.5 Ensure icmpaddressmask is disabled

Information

The icmpaddressmask parameter determines whether the system responds to an ICMP address mask ping.

The icmpaddressmask parameter will be set to 0 This means that the system will not respond to ICMP address mask request pings. By default, when this is enabled the system is susceptible to source routing attacks. This is typically a feature performed by a device such as a network router and should not be enabled within the operating system.

Solution

In /etc/tunables/nextboot add the icmpaddressmask entry:

no -p -o icmpaddressmask=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 95c108fa351db3a82d8590bf4c161cf41e13fd454d9d379ff66f3258afc6a64b