3.12 Set Strict Multihoming

Information

These settings control whether a packet arriving on a non-forwarding interface can be accepted for an IP address that is not explicitly configured on that interface.

Enable this setting for systems that have interfaces that cross strict networking domains (for example, a firewall or a VPN node).

Solution

To enforce this setting for IPv4 packets, run the following command:

# ipadm set-prop -p _strict_dst_multihoming=1 ipv4

To enforce this setting for IPv6 packets, run the following command:

# ipadm set-prop -p _strict_dst_multihoming=1 ipv6

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: ccf3c1cd924b18c5f19358df304fef918b0be56e7574c05d01c1eb380e4c12c5