SV-258889r991589_rule
V-258889
SRG-OS-000480-GPOS-00227
PHTN-40-000226
CAT II
10
Navigate to and open:
/etc/sysctl.d/zz-stig-hardening.conf
Add or update the following lines:
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
At the command line, run the following command to load the new configuration:
# /sbin/sysctl --load /etc/sysctl.d/zz-stig-hardening.conf
Note: If the file zz-stig-hardening.conf does not exist, it must be created.
At the command line, run the following command to verify ICMP secure redirects are not accepted:
# /sbin/sysctl -a --pattern "net.ipv4.conf.(all|default).secure_redirects"
Expected result:
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
If the "secure_redirects" kernel parameters are not set to "0", this is a finding.
V-258889
False
PHTN-40-000226
At the command line, run the following command to verify ICMP secure redirects are not accepted:
# /sbin/sysctl -a --pattern "net.ipv4.conf.(all|default).secure_redirects"
Expected result:
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
If the "secure_redirects" kernel parameters are not set to "0", this is a finding.
M
5569