4.5.13 Ensure ip6srcrouteforward is disabled

Information

The ip6srcrouteforward parameter determines whether or not the system forwards IPV6 source-routed packets.

The ip6srcrouteforward parameter will be set to 0, to prevent source-routed packets being forwarded by the system. This would prevent a hacker from using source-routed packets to bridge an external facing server to an internal LAN, possibly even through a firewall.

Solution

Run the following command to set the ip6srcrouteforward entry:

no -p -o ip6srcrouteforward=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: ac1e57b468ecad0fa12958d1d6f8d98a1eff43f0a8050832c1c461ce0fcdfc8d