Network Security - Ensure IP directed broadcast has not been configured

Information

A directed broadcast occurs when a packet is sent to the broadcast address of a subnet. IP directed broadcast packets traverse the network in the same way as unicast IP packets until they reach the destination subnet. When they reach the destination subnet, and if IP directed broadcast is enabled on the last device in the path, the router or switch translates (explodes) the IP directed broadcast packet into a broadcast that floods the packet on the target subnet.

NOTE: Nessus is checking for directed broadcast by the existence of targeted-broadcast options.

Solution

Review the configuration and verify that 'targeted-broadcast' is not configured on any interfaces.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11)

Plugin: Juniper

Control ID: 2513a94601165d7d85f2be0528a05a6ae476c95d651add28f849a8047e8babc7