Skip to content

The Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.

An XCCDF Rule

Description

ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages contain information from the system's route table, possibly revealing portions of the network topology.

ID
SV-258890r933731_rule
Version
PHTN-40-000227
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Navigate to and open:

/etc/sysctl.d/zz-stig-hardening.conf

Add or update the following lines: