4.5.12 Ensure ipsrcroutesend is disabled

Information

The ipsrcroutesend parameter determines whether or not the system can send source-routed packets.

The ipsrcroutesend parameter will be set to 0 to ensure that any local applications cannot send source routed packets.

Solution

In /etc/tunables/nextboot add the ipsrcroutesend entry:

no -p -o ipsrcroutesend=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 1c3bcbe696efd70bb990301d0eaf5f14450520bdf25d69bb75935494ac5c71c2