NET-IPV6-016 - The network element must be configured so that ICMPv6 unreachable notifications and redirects are disabled on all external facing interfaces.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Internet Control Message Protocol version 6 (ICMPv6) supports IPv6 traffic by relaying information about paths, routes, and network conditions. Routers automatically send ICMPv6 messages under a wide variety of conditions. ICMPv6 messages are commonly used by attackers for network mapping and diagnosis: Host unreachable and Redirect.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

The network element configuration must be changed to ensure ICMPv6 unreachables and redirects are disabled at all external interfaces.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CAT|II, Rule-ID|SV-16478r2_rule, STIG-ID|NET-IPV6-016, Vuln-ID|V-14670

Plugin: Juniper

Control ID: 5a67a4e9e1eb49a5e97e50dd43d271e946ab6be5ec689fc1611548fa405623da