1.127 SOL-11.1-050100

Information

The system must disable TCP reverse IP source routing.

GROUP ID: V-216377
RULE ID: SV-216377r959010

If enabled, reverse IP source routing would allow an attacker to more easily complete a three-way TCP handshake and spoof new connections.

Solution

The Network Management profile is required.

Disable reverse source routing.

# pfexec ipadm set-prop -p _rev_src_routes=0 tcp

See Also

https://workbench.cisecurity.org/benchmarks/23765