AIX7-00-003134 - AIX must not process ICMP timestamp requests.

Information

The processing of Internet Control Message Protocol (ICMP) timestamp requests increases the attack surface of the system.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

From the command prompt, run the following commands to create and activate 'ipsec_v4' and 'ipsec_v6' devices:
# mkdev -l ipsec -t 4
# mkdev -l ipsec -t 6

Run the following commands to create 2 IPsec rules to block the ICMP timestamp request and reply:
# genfilt -v 4 -a D -s 0 -m 0 -d 0 -M 0 -c icmp -O eq -P 13 -r B -w I -i all
# genfilt -v 4 -a D -s 0 -m 0 -d 0 -M 0 -c icmp -o eq -p 14 -r B -w O -i all

From the command prompt, run the following command to activate all the filter rules in the rule database:
# mkfilt -u

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215429r991589_rule, STIG-ID|AIX7-00-003134, STIG-Legacy|SV-101817, STIG-Legacy|V-91719, Vuln-ID|V-215429

Plugin: Unix

Control ID: f111523d37eb5c61c0afe20073ba43b26a337c9fb93d49e8563fc9f06111756b