Skip to content

The Photon operating system must log IPv4 packets with impossible addresses.

An XCCDF Rule

Description

The presence of "martian" packets (which have impossible addresses) as well as spoofed packets, source-routed packets, and redirects could be a sign of nefarious network activity. Logging these packets enables this activity to be detected.

ID
SV-258891r933734_rule
Version
PHTN-40-000228
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Navigate to and open:

/etc/sysctl.d/zz-stig-hardening.conf

Add or update the following lines: