OL6-00-000090 - The system must not accept ICMPv4 secure redirect packets by default.

Information

Accepting 'secure' ICMP redirects (from those gateways listed as default gateways) has few legitimate uses. It should be disabled unless it is absolutely required.

Solution

To set the runtime status of the 'net.ipv4.conf.default.secure_redirects' kernel parameter, run the following command:

# sysctl -w net.ipv4.conf.default.secure_redirects=0

If this is not the system's default value, add the following line to '/etc/sysctl.conf':

net.ipv4.conf.default.secure_redirects = 0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-208858r793643_rule, STIG-ID|OL6-00-000090, STIG-Legacy|SV-64857, STIG-Legacy|V-50651, Vuln-ID|V-208858

Plugin: Unix

Control ID: bc2fb74edd2f5704fbd876c6cc3869f540123d2a3d788e15a3c7fefc4a12c918