SonicWALL - Detection Prevention - ICMP packets

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SonicWALL - Detection Prevention - Never generate ICMP Time-Exceeded packets. The SonicWALL appliance generates Time-Exceeded packets to report when it has dropped a packet because its TTL value has decreased to zero. Select this option if you do not want the SonicWALL appliance to generate these reporting packets.

Solution

Navigate to Firewall Settings->Advanced->Detection Prevention and check off 'Never generate ICMP Time-Exceeded packets' and 'Decrement IP TTL for forwarded traffic'.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7

Plugin: SonicWALL

Control ID: 57ca86177dfbb3cb51fa7e729e871a18a99767889ab92dd6f115ecd523d2d6cf