Network Security - Disable ICMP timestamp & record route requests - no-ping-time-stamp

Information

When the ping command is used with the record-route option, the Routing Engine displays the path of the ICMP echo request packets and timestamps in the ICMP echo responses. This is useful for troubleshooting network path problems because, unlike the traceroute command, it also shows the return route instead of just the path to the destination.

The possible security implication is that the timestamp and record route option allows someone to map your network and reveal private information, such as loopback addresses. Use the commands below to disable the ping, record-route, and timestamp options

Solution

Configure the system to disable timestamps in the ICMP echo responses.

user@host# edit system
user@host# set no-ping-time-stamp

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Juniper

Control ID: 93e53c800357013c23a7c82e043de00214a0cfa69dfc67de8b467373fc905df2