NET-IPV6-059 - The administrator must ensure that the maximum hop limit is at least 32.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Neighbor Discovery protocol allows a hop limit value to be advertised by routers in a Router Advertisement message to be used by hosts instead of the standardized default value. If a very small value was configured and advertised to hosts on the LAN segment, communications would fail due to hop limit reaching zero before the packets sent by a host reached its destination.

Solution

Configure maximum hop limit to at least 32.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|III, Rule-ID|SV-40390r1_rule, STIG-ID|NET-IPV6-059, Vuln-ID|V-30617

Plugin: Juniper

Control ID: c9ca8d8c31f40eae5c853ba3fc96f18aadb4a1d846fa3593bfe7c6aa2b32325b