SV-256034r882444_rule
V-256034
SRG-NET-000362-RTR-000115
ARST-RT-000550
CAT II
10
Step 1: Disable ICMP redirects on all external interfaces.
ip access-group DENY_REDIRECT
deny icmp any any redirect
permit ip any any
Step 2: Apply the ACL outbound on interfaces.
interface Ethernet 2
description EXTERNAL INTERFACE
ip access-group DENY_REDIRECT in
Review the device configuration to determine if controls have been defined to ensure the router does not send ICMP Redirect messages out to any external interfaces.
Step 1: To verify the ACL is configured to determine the router does not send ICMP Redirect messages out to any external interfaces, execute the command "sh ip access-list".
ip access-group DENY_REDIRECT
deny icmp any any redirect
permit ip any any
Step 2: To verify the ACL is applied outbound on interface, execute the command "sh run int Eth YY".
interface Ethernet 2
ip access-group DENY_REDIRECT out
If ICMP Redirect messages are enabled on any external interfaces, this is a finding.
V-256034
False
ARST-RT-000550
Review the device configuration to determine if controls have been defined to ensure the router does not send ICMP Redirect messages out to any external interfaces.
Step 1: To verify the ACL is configured to determine the router does not send ICMP Redirect messages out to any external interfaces, execute the command "sh ip access-list".
ip access-group DENY_REDIRECT
deny icmp any any redirect
permit ip any any
Step 2: To verify the ACL is applied outbound on interface, execute the command "sh run int Eth YY".
interface Ethernet 2
ip access-group DENY_REDIRECT out
If ICMP Redirect messages are enabled on any external interfaces, this is a finding.
M
5513