4.5.11 Ensure ipsrcrouterecv is disabled

Information

The ipsrcrouterecv parameter determines whether the system accepts source routed packets.

The ipsrcrouterecv parameter will be set to 0, This means that the system will not accept source routed packets. By default, when this is enabled the system is susceptible to source routing attacks.

Solution

Run the following command to set the ipsrcrouterecv entry:

no -p -o ipsrcrouterecv=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 771c9ae21263709e73a4f2898e6aee27868633baf6e6a878e417827800978184