SV-217020r639663_rule
V-217020
SRG-NET-000205-RTR-000002
JUNI-RT-000140
CAT II
10
Configure the filter that is applied inbound to the loopback interface to drop all fragmented ICMP packets as shown in the example below.
[edit firewall family inet filter DESTINED_TO_RP]
set term BLOCK_ICMP_FRAG from protocol icmp is-fragment
set term BLOCK_ICMP_FRAG then discard
insert term BLOCK_ICMP_FRAG before term DENY_BY_DEFAULT
Review the filter that is applied inbound to the loopback interface and verify that it discards fragmented ICMP packets as shown in the example below.
firewall {
family inet {
…
…
…
}
filter DESTINED_TO_RE {
…
…
…
}
term BLOCK_ICMP_FRAG {
from {
is-fragment;
protocol icmp;
}
then {
discard;
}
}
term ICMP_ANY {
from {
protocol icmp;
}
then accept;
}
term DENY_BY_DEFAULT {
then {
log;
discard;
}
}
}
}
If the router is not configured to filter to drop all fragmented ICMP packets destined to itself, this is a finding.
V-217020
False
JUNI-RT-000140
Review the filter that is applied inbound to the loopback interface and verify that it discards fragmented ICMP packets as shown in the example below.
firewall {
family inet {
…
…
…
}
filter DESTINED_TO_RE {
…
…
…
}
term BLOCK_ICMP_FRAG {
from {
is-fragment;
protocol icmp;
}
then {
discard;
}
}
term ICMP_ANY {
from {
protocol icmp;
}
then accept;
}
term DENY_BY_DEFAULT {
then {
log;
discard;
}
}
}
}
If the router is not configured to filter to drop all fragmented ICMP packets destined to itself, this is a finding.
M
4032