3.2 Disable Response to ICMP Broadcast Netmask Requests

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This setting controls whether Solaris will respond to ICMP broadcast netmask requests.

Rationale:

Reduce attack surface by restricting this vector used for host and network discovery and to
prevent denial of service attacks.

Solution

To enforce this setting, use the command:

# ipadm set-prop -p _respond_to_address_mask_broadcast=0 ip

See Also

https://workbench.cisecurity.org/files/2582