GEN003603 - The system must not respond to ICMPv4 echoes sent to a broadcast address.

Information

Responding to broadcast Internet Control Message Protocol (ICMP) echoes facilitates network mapping and provides a vector for amplification attacks.

Solution

Configure the system to ignore ICMP ECHO_REQUESTs sent to broadcast addresses.

# no -po bcastping=0

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip