SV-45716r2_rule
V-34788
SRG-NET-000273-IDPS-00198
SRG-NET-000273-IDPS-00198
CAT II
10
Configure the IDPS to block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
An acceptable alternative to blocking all Destination Unreachable responses is to filter Destination Unreachable messages generated by the firewall implementation to allow ICMP Destination Unreachable--
Fragmentation Needed but DF Bit Set (Type 3, Code 4) and apply this filter to the external interfaces.
Verify the IDPS blocks outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
If the IDPS does not block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages, this is a finding.
V-34788
False
SRG-NET-000273-IDPS-00198
Verify the IDPS blocks outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
If the IDPS does not block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages, this is a finding.
M
2358