4.5.7 Ensure ip6forwarding is disabled

Information

The ip6forwarding parameter determines whether or not the system forwards IPv6 TCP/IP packets.

The ip6forwarding parameter will be set to 0, to ensure that redirected packets do not reach remote networks. This should only be enabled if the system is performing the function of an IP router. This is typically handled by a dedicated network device.

Solution

Run the following command to set the ip6forwarding entry:

no -p -o ip6forwarding=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: f9b8a1daf2e18deb04cbb95e267a581172b3fe89498f5dceb390d6d9a9786bc9