4.5.4 Ensure directed_broadcast is disabled

Information

The directed_broadcast parameter determines whether or not the system allows a directed broadcast to a network gateway.

The directed_broadcast parameter will be set to 0 to prevent directed broadcasts being sent network gateways. This would prevent a redirected packet from reaching a remote network.

Solution

In /etc/tunables/nextboot add the directed_broadcast entry:

no -p -o directed_broadcast=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 0bde2bb6575f46f0a0ab62c8136d636d5572cd3944a1245ab46135df9c0c0dcc