OL6-00-000091 - The system must ignore ICMPv4 redirect messages by default.

Information

This feature of the IPv4 protocol has few legitimate uses. It should be disabled unless it is absolutely required.

Solution

To set the runtime status of the 'net.ipv4.conf.default.accept_redirects' kernel parameter, run the following command:

# sysctl -w net.ipv4.conf.default.accept_redirects=0

If this is not the system's default value, add the following line to '/etc/sysctl.conf':

net.ipv4.conf.default.accept_redirects = 0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-208859r793644_rule, STIG-ID|OL6-00-000091, STIG-Legacy|SV-64861, STIG-Legacy|V-50655, Vuln-ID|V-208859

Plugin: Unix

Control ID: be53deab23492722fa7064af49fd95fdef305b2ac4a020278db0ea03aff3b638