Check: GEN007880
Solaris 9 X86 STIG:
GEN007880
(in version v1 r9)
Title
The system must not send IPv6 ICMP redirects. (Cat II impact)
Discussion
ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages contain information from the system's route table revealing portions of the network topology.
Check Content
Verify the system is configured to not send IPv6 ICMP redirect messages. # ndd /dev/ip6 ip6_send_redirects If the returned value is not 0, this is a finding.
Fix Text
Configure the system to not send IPv6 ICMP redirect messages. # ndd -set /dev/ip6 ip6_send_redirects 0 Also, add this command to a system startup script.
Additional Identifiers
Rule ID: SV-26938r1_rule
Vulnerability ID: V-22551
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001551 |
The organization defines approved authorizations for controlling the flow of information between interconnected systems. |
Controls
Number | Title |
---|---|
AC-4 |
Information Flow Enforcement |