Network Security - Disable ICMP timestamp & record route requests - no-ping-record-route

Information

When the ping command is used with the record-route option, the Routing Engine displays the path of the ICMP echo request packets and timestamps in the ICMP echo responses. This is useful for troubleshooting network path problems because, unlike the traceroute command, it also shows the return route instead of just the path to the destination.

The possible security implication is that the timestamp and record route option allows someone to map your network and reveal private information, such as loopback addresses. Use the commands below to disable the ping, record-route, and timestamp options

Solution

Configure the system to disable route recording in the ICMP echo responses.

user@host# edit system
user@host# set no-ping-record-route

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Juniper

Control ID: 524e62fdf31715a5a7dbaac62eb870447f6fdc7c1c25c1d3c827f8ae265340d6