SV-227800r603266_rule
V-227800
SRG-OS-000480
GEN003607
CAT II
10
Edit /etc/ipf/ipf.conf and add rules to block incoming source-routed packets, such as:
block in log quick all with opt lsrr
block in log quick all with opt ssrr
Reload the IPF rules.
Procedure:
# ipf -Fa -A -f /etc/ipf/ipf.conf
Determine the type of zone that you are currently securing.
# zonename
If the zone is not the global zone, determine if any interfaces are exclusive to the zone:
# dladm show-link
If the output indicates "insufficient privileges" then this requirement is not applicable.
If the zone is the global zone or the non-global zone has exclusive interfaces check the system for an IPF rule blocking incoming source-routed packets.
Procedure: # ipfstat -i
Examine the list for rules such as:
block in log quick all with opt lsrr
block in log quick all with opt ssrr
If the listed rules do not block incoming traffic with both lsrr and ssrr options, this is a finding.
V-227800
False
GEN003607
Determine the type of zone that you are currently securing.
# zonename
If the zone is not the global zone, determine if any interfaces are exclusive to the zone:
# dladm show-link
If the output indicates "insufficient privileges" then this requirement is not applicable.
If the zone is the global zone or the non-global zone has exclusive interfaces check the system for an IPF rule blocking incoming source-routed packets.
Procedure: # ipfstat -i
Examine the list for rules such as:
block in log quick all with opt lsrr
block in log quick all with opt ssrr
If the listed rules do not block incoming traffic with both lsrr and ssrr options, this is a finding.
M
4061