6.21 Ensure ICMP Redirects are Disabled for IPv4

Information

The Routing Engine should not send ICMP Redirect Messages.

Rationale:

ICMP Redirect Messages provide a method for a router to communicate routing information with a host and is intended for use when a router receives packets to forward to a destination to which the host should have a direct route. In a well designed, modern, network ICMP Redirects should not be needed or add any useful functionality.

An attacker may abuse this feature to obtain topology information about a target network and potentially identify weaknesses for later exploitation or to target the router or hosts with a Denial of Service (DoS) or Man in the Middle (MITM) attacks.

To prevent this abuse, ICMP Redirect message generation should be disabled globally where it is not required.

Impact:

In some networks, for instances where subnets populated by hosts include multiple non-redundant gateways, removing redirects may result in traffic being doubled on some gateways interfaces as traffic is received and then forwarded on the same port.

Solution

To disable ICMP redirects globally for IPv4, issue the following command from the [edit system] heirachy:

[edit system]
user@host# set no-redirects

Default Value:

JUNOS devices send ICMP Redirect messages by default.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: 728025273f49f9977806b51d333779a81188c718ee2c6926df1e82c644f20102