6.17 Ensure Ping Timestamps are Set to Disabled

Information

The Routing Engine should not return Timestamp information to Ping Requests

Rationale:

When the Timestamp Request option is set in a Echo Request (ping) packet, a host generally responds with its current system time when the ping is received.

Attackers may use Echo Requests with the Timestamp option set during recognizance of a network to obtain details of the configuration and state.

The use of these options is largely deprecated, with no valid usage in almost all modern networks; therefore, the JUNOS Device should be configured not to return the Timestamp in ICMP Echo Responses.

Impact:

ICMP Echo Requests (pings) with the Request Timestamp Option set will still receive a response (unless blocked elsewhere), but the JUNOS Device will not return the additional Timestamp information.

Solution

To ignore Echo Requests with the Timestamp Request option set, issue the following command from the [edit system] hierarchy;

[edit system]
user@host#set no-ping-time-stamp

Default Value:

By default the Routing Engine responds to Echo Requests with the Timestamp Request option set, including the current system time of the router.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: f8af9c5a88e984efe3dd731c6f4b75858d27a3547271bd922998d3a31aecc3b1