3.6 Disable Directed Broadcast Packet Forwarding

Information

This setting controls whether Solaris forwards broadcast packets for a specific network if it is directly connected to the machine.

Rationale:

Keep this parameter disabled to prevent denial of service attacks.

Solution

To enforce this setting, run the following command:

# ipadm set-prop -p _forward_directed_broadcasts=0 ip

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 1f9727e3cc5d734c13ce65ebb4e4a1faf06deeab63da59b98fbec42d6cf5b765