GEN007820 - The system must not have IP tunnels configured - 'lstun -a'

Information

IP tunneling mechanisms can be used to bypass network filtering.

Solution

Remove the configuration for any IP tunnels from the system.
Remove tunnels listed with the lstun command.
#rmtun -t <Tunnel id> -d
Remove the tunneled IP interfaces.
#ifconfig <if name> detach
#rmdev -Rdl <if name>

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip