Check: GEN003606
HP-UX 11.31 STIG:
GEN003606
(in versions v1 r19 through v1 r14)
Title
The system must prevent local applications from generating source-routed packets. (Cat II impact)
Discussion
Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures.
Check Content
Check the system for an IP Filter (IPF) rule blocking outgoing source-routed packets. # ipfstat -o Examine the list for rules such as: block out log quick [all] | [from any to any] with opt lsrr block out log quick [all] | [from any to any] with opt ssrr If the listed rules do not block both lsrr and ssrr options, this is a finding.
Fix Text
Edit /etc/opt/ipf/ipf.conf and add rules to block outgoing source-routed packets, such as: block out log quick [all] | [from any to any] with opt lsrr block out log quick [all] | [from any to any] with opt ssrr Reload the IPF rules: # ipf -Fa -A -f /etc/opt/ipf/ipf.conf
Additional Identifiers
Rule ID: SV-29707r2_rule
Vulnerability ID: V-22413
Group Title: GEN003606
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001551 |
The organization defines approved authorizations for controlling the flow of information between interconnected systems. |
Controls
Number | Title |
---|---|
AC-4 |
Information Flow Enforcement |