GEN005570 - The system must be configured with a default gateway for IPv6 if the system uses IPv6, unless the system is a router.

Information

If a system has no default gateway defined, the system is at increased risk of man-in-the-middle, monitoring, and Denial of Service attacks.

Solution

Add a default route for IPv6.
Edit /etc/sysconfig/network-scripts/ifcfg-eth0 (substitute interface as appropriate).
Add an IPV6_DEFAULTGW=<gateway> configuration setting.
Restart the interface.
# ifdown eth0; ifup eth0

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-22490, Rule-ID|SV-37921r1_rule, STIG-ID|GEN005570, Vuln-ID|V-22490

Plugin: Unix

Control ID: 63465804c5865c626ab969bbcbef5a335728ea2540eb5ec3ceca52e24f1d5578