STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

The Photon operating system must not perform IPv4 packet forwarding.

DISA Rule

SV-258893r991589_rule

Vulnerability Number

V-258893

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

PHTN-40-000231

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to and open:

/etc/sysctl.d/zz-stig-hardening.conf

Add or update the following line:

net.ipv4.ip_forward = 0

At the command line, run the following command to load the new configuration:

# /sbin/sysctl --load /etc/sysctl.d/zz-stig-hardening.conf

Note: If the file zz-stig-hardening.conf does not exist, it must be created.

Check Contents

If IP forwarding is required, for example if Kubernetes is installed, this is Not Applicable.

At the command line, run the following command to verify packet forwarding it disabled:

# /sbin/sysctl net.ipv4.ip_forward

Expected result:

net.ipv4.ip_forward = 0

If the "net.ipv4.ip_forward" kernel parameter is not set to "0", this is a finding.

Vulnerability Number

V-258893

Documentable

False

Rule Version

PHTN-40-000231

Severity Override Guidance

If IP forwarding is required, for example if Kubernetes is installed, this is Not Applicable.

At the command line, run the following command to verify packet forwarding it disabled:

# /sbin/sysctl net.ipv4.ip_forward

Expected result:

net.ipv4.ip_forward = 0

If the "net.ipv4.ip_forward" kernel parameter is not set to "0", this is a finding.

Check Content Reference

M

Target Key

5569