GEN003610 - The system must not send IPv4 ICMP redirects.

Information

ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages contain information from the system's route table that could reveal portions of the network topology.

Solution

Configure the system to not send IPv4 ICMP redirect messages.

Procedure:
# ndd -set /dev/ip ip_send_redirects 0

Also add this command to a system startup script.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-226898r603265_rule, STIG-ID|GEN003610, STIG-Legacy|SV-26632, STIG-Legacy|V-22417, Vuln-ID|V-226898

Plugin: Unix

Control ID: 6f55c4ffad0b657b3b51929d9f279b6f70f45ade9e58cac9ea3ae2fd6534df00