4.5.7 Ensure ip6forwarding is disabled

Information

The ip6forwarding parameter determines whether or not the system forwards IPv6 TCP/IP packets.

The ip6forwarding parameter will be set to 0 to ensure that redirected packets do not reach remote networks. This should only be enabled if the system is performing the function of an IP router. This is typically handled by a dedicated network device.

Solution

In /etc/tunables/nextboot add the ip6forwarding entry:

no -p -o ip6forwarding=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: f9b8a1daf2e18deb04cbb95e267a581172b3fe89498f5dceb390d6d9a9786bc9