4.5.9 Ensure ipsendredirects is disabled

Information

The ipsendredirects parameter determines whether or not the system forwards re-directed TCP/IP packets.

The ipsendredirects parameter will be set to 0 to ensure that redirected packets do not reach remote networks.

Solution

In /etc/tunables/nextboot add the ipsendredirects entry:

no -p -o ipsendredirects=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 4f8edfa6dcb3236eb4ab9eba0892c94768efe53c8c4020012587752d165b9e8d