OL6-00-000092 - The system must not respond to ICMPv4 sent to a broadcast address.

Information

Ignoring ICMP echo requests (pings) sent to broadcast or multicast addresses makes the system slightly more difficult to enumerate on the network.

Solution

To set the runtime status of the 'net.ipv4.icmp_echo_ignore_broadcasts' kernel parameter, run the following command:

# sysctl -w net.ipv4.icmp_echo_ignore_broadcasts=1

If this is not the system's default value, add the following line to '/etc/sysctl.conf':

net.ipv4.icmp_echo_ignore_broadcasts = 1

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-208860r793645_rule, STIG-ID|OL6-00-000092, STIG-Legacy|SV-64863, STIG-Legacy|V-50657, Vuln-ID|V-208860

Plugin: Unix

Control ID: 14b4eb0041d36c60d105d9163bc5b55424ef8cc422ec4c72a66b16d5d161df9f