OL6-00-000093 - The system must ignore ICMPv4 bogus error responses.

Information

Ignoring bogus ICMP error responses reduces log size, although some activity would not be logged.

Solution

To set the runtime status of the 'net.ipv4.icmp_ignore_bogus_error_responses' kernel parameter, run the following command:

# sysctl -w net.ipv4.icmp_ignore_bogus_error_responses=1

If this is not the system's default value, add the following line to '/etc/sysctl.conf':

net.ipv4.icmp_ignore_bogus_error_responses = 1

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-208861r793646_rule, STIG-ID|OL6-00-000093, STIG-Legacy|SV-64869, STIG-Legacy|V-50663, Vuln-ID|V-208861

Plugin: Unix

Control ID: c81c10e90c7f46177003992ade7ca94a511c227cee70c0ba15f7c7bb53711d70