4.5.10 Ensure ipsrcrouteforward is disabled

Information

The ipsrcrouteforward parameter determines whether or not the system forwards IPV4 source-routed packets.

The ipsrcrouteforward will be set to 0, to prevent source-routed packets being forwarded by the system. This would prevent a hacker from using source-routed packets to bridge an external facing server to an internal LAN, possibly even through a firewall.

Solution

Run the following command to set the ipsrcrouteforward entry:

no -p -o ipsrcrouteforward=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: f1081d7e9955462fae265e14515a9f9850e85b24719611f60f1ed065d6b88715