SV-221880r603260_rule
V-221880
SRG-OS-000480-GPOS-00227
OL07-00-040650
CAT II
10
Configure the system not to allow interfaces to perform IPv4 ICMP redirects by default.
Set the system to the required kernel parameter by adding the following line to "/etc/sysctl.conf" or a configuration file in the /etc/sysctl.d/ directory (or modify the line to have the required value):
net.ipv4.conf.default.send_redirects = 0
Issue the following command to make the changes take effect:
# sysctl --system
Verify the system does not allow interfaces to perform IPv4 ICMP redirects by default.
# grep 'net.ipv4.conf.default.send_redirects' /etc/sysctl.conf /etc/sysctl.d/*
If "net.ipv4.conf.default.send_redirects" is not configured in the "/etc/sysctl.conf" file or in the /etc/sysctl.d/ directory, is commented out or does not have a value of "0", this is a finding.
Check that the operating system implements the "default send_redirects" variables with the following command:
# /sbin/sysctl -a | grep 'net.ipv4.conf.default.send_redirects'
net.ipv4.conf.default.send_redirects = 0
If the returned line does not have a value of "0", this is a finding.
V-221880
False
OL07-00-040650
Verify the system does not allow interfaces to perform IPv4 ICMP redirects by default.
# grep 'net.ipv4.conf.default.send_redirects' /etc/sysctl.conf /etc/sysctl.d/*
If "net.ipv4.conf.default.send_redirects" is not configured in the "/etc/sysctl.conf" file or in the /etc/sysctl.d/ directory, is commented out or does not have a value of "0", this is a finding.
Check that the operating system implements the "default send_redirects" variables with the following command:
# /sbin/sysctl -a | grep 'net.ipv4.conf.default.send_redirects'
net.ipv4.conf.default.send_redirects = 0
If the returned line does not have a value of "0", this is a finding.
M
4089