1.125 SOL-11.1-050080

Information

The system must set strict multihoming.

GROUP ID: V-216375
RULE ID: SV-216375r959010

These settings control whether a packet arriving on a non-forwarding interface can be accepted for an IP address that is not explicitly configured on that interface.

This rule is NA for documented systems that have interfaces that cross strict networking domains (for example, a firewall, a router, or a VPN node).

Solution

The Network Management profile is required.

Disable strict multihoming for IPv4 and IPv6.

# pfexec ipadm set-prop -p _strict_dst_multihoming=1 ipv4
# pfexec ipadm set-prop -p _strict_dst_multihoming=1 ipv6

See Also

https://workbench.cisecurity.org/benchmarks/23765