3.13 Disable ICMP Redirect Messages - persistent ipv6 = off

Information

These setting controls whether Solaris sends ICMPv4 and ICMPv6 redirect messages.

A malicious user can exploit the ability of the system to send ICMP redirects by continually
sending packets to the system, forcing the system to respond with ICMP redirect messages,
resulting in an adverse impact on the CPU performance of the system.

Solution

To enforce this setting for IPv4 packets, use the command-# ipadm set-prop -p send_redirects=off ipv4To enforce this setting for IPv6 packets, use the command-# ipadm set-prop -p send_redirects=off ipv6

See Also

https://workbench.cisecurity.org/files/616

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Unix

Control ID: 3ac955ce47bf56e91b7f3a6053cc08b3a7ce6cfc8026b442a74ccff4a569de5e