Check: GEN003609
SUSE Linux Enterprise Server v11 for System z STIG:
GEN003609
(in versions v1 r12 through v1 r9)
Title
The system must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages. (Cat II impact)
Discussion
ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages modify the host's route table and are unauthenticated. An illicit ICMP redirect message could result in a man-in-the-middle attack.
Check Content
Verify the system does not accept IPv4 ICMP redirect messages. # grep [01] /proc/sys/net/ipv4/conf/*/accept_redirects|egrep "default|all" If all of the resulting lines do not end with "0", this is a finding.
Fix Text
Configure the system to not accept IPv4 ICMP redirect messages. Edit /etc/sysctl.conf and add a setting for "net.ipv4.conf.all.accept_redirects=0" and "net.ipv4.conf.default.accept_redirects=0". # sysctl -p
Additional Identifiers
Rule ID: SV-45726r1_rule
Vulnerability ID: V-22416
Group Title: GEN003609
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001503 |
The organization controls changes to the configuration settings in accordance with organizational policies and procedures. |
CCI-001551 |
The organization defines approved authorizations for controlling the flow of information between interconnected systems. |