Skip to content

The system must ignore ICMP redirect messages.

An XCCDF Rule

Description

Ignoring ICMP redirect messages reduces the likelihood of denial of service attacks.

ID
SV-216374r959010_rule
Version
SOL-11.1-050070
Severity
Low
References
Updated

Remediation Templates

A Manual Procedure

The Network Management profile is required.

Disable ignore redirects for IPv4 and IPv6.

# pfexec ipadm set-prop -p _ignore_redirect=1 ipv4
# pfexec ipadm set-prop -p _ignore_redirect=1 ipv6