3.11 Ignore ICMP Redirect Messages

Information

These settings control whether Solaris will ignore ICMP redirect messages.

Rationale:

IP redirects should not be necessary in a well-designed and maintained network. Set to a value of 1 if there is a high risk for a DoS attack. Otherwise, the default value of 0 is sufficient.

Solution

To enforce this setting for IPv4 packets, run the following command:

# ipadm set-prop -p _ignore_redirect=1 ipv4

To enforce this setting for IPv6 packets, run the following command:

# ipadm set-prop -p _ignore_redirect=1 ipv6

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 42103fbf52e6ec80ba7a3c058cbd3f1922c349ac6c53dc8a090edc6b0b7d465c