OL6-00-000084 - The system must not accept ICMPv4 redirect packets on any interface.

Information

Accepting ICMP redirects has few legitimate uses. It should be disabled unless it is absolutely required.

Solution

To set the runtime status of the 'net.ipv4.conf.all.accept_redirects' kernel parameter, run the following command:

# sysctl -w net.ipv4.conf.all.accept_redirects=0

If this is not the system's default value, add the following line to '/etc/sysctl.conf':

net.ipv4.conf.all.accept_redirects = 0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-208854r793639_rule, STIG-ID|OL6-00-000084, STIG-Legacy|SV-65177, STIG-Legacy|V-50971, Vuln-ID|V-208854

Plugin: Unix

Control ID: 1650796d77535f6c9b9d3faa5f03ae6e4feae617c994aa71ede1a7d03671c705