4.2.3 Disable Secure ICMP Redirect Acceptance 'net.ipv4.conf.default.secure_redirects = 0'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Configuration Level : Level-II

Solution

Set the net.ipv4.conf.all.secure_redirects and net.ipv4.conf.default.secure_redirects parameters to 0 in /etc/sysctl.conf:
net.ipv4.conf.all.secure_redirects=0
net.ipv4.conf.default.secure_redirects=0

Modify active kernel parameters to match:
/sbin/sysctl -w net.ipv4.conf.all.secure_redirects=0
/sbin/sysctl -w net.ipv4.conf.default.sec

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-6, 800-53|SC-7(12), CCE|CCE-3339-9, CCE|CCE-3472-8, CSCv6|9.2

Plugin: Unix

Control ID: 3db43593d2c79294d9175d39edc08deebfd0d4f2566b9d7b21ef1cb8b29e31e2