3.5 Disable Source Packet Forwarding

Information

This setting controls whether the IPv4 or IPv6 configuration will forward packets with IPv4 routing options or IPv6 routing headers.

Keep this parameter disabled to prevent denial of service attacks through spoofed packets.

Solution

To enforce this setting for IPv4 packets, run the following command:

# ipadm set-prop -p _forward_src_routed=0 ipv4

To enforce this setting for IPv6 packets, run the following command:

# ipadm set-prop -p _forward_src_routed=0 ipv6

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 5b6a9c880d94169f8d4b70b09dd7c34893bb95f948e6720160ba266918ac843e