3.13 Disable ICMP Redirect Messages

Information

These settings control whether Solaris sends ICMPv4 and ICMPv6 redirect messages.

Rationale:

A malicious user can exploit the ability of the system to send ICMP redirects by continually sending packets to the system, forcing the system to respond with ICMP redirect messages, resulting in an adverse impact on the CPU performance of the system.

Solution

To enforce this setting for IPv4 packets, run the following command:

# ipadm set-prop -p send_redirects=off ipv4

To enforce this setting for IPv6 packets, run the following command:

# ipadm set-prop -p send_redirects=off ipv6

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 8a63d088ed447bd49d3dd55e7db47a55977b4d5cecb6c7d545b1fab0dff69516