SV-215301r508663_rule
V-215301
SRG-OS-000480-GPOS-00227
AIX7-00-002118
CAT II
10
Edit the "/etc/sshd/sshd_config" file to add the following line and save the change:
AllowTcpForwarding no
Restart the SSH daemon:
# stopsrc -s sshd
# startsrc -s sshd
If TCP forwarding is approved for use by the ISSO, this is not applicable.
Check the SSH daemon configuration for the "AllowTcpForwarding" directive using command:
# grep -i AllowTcpForwarding /etc/ssh/sshd_config | grep -v '^#'
AllowTcpForwarding no
If the setting is not present or the setting is "yes", this is a finding.
V-215301
False
AIX7-00-002118
If TCP forwarding is approved for use by the ISSO, this is not applicable.
Check the SSH daemon configuration for the "AllowTcpForwarding" directive using command:
# grep -i AllowTcpForwarding /etc/ssh/sshd_config | grep -v '^#'
AllowTcpForwarding no
If the setting is not present or the setting is "yes", this is a finding.
M
4012