The Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
An XCCDF Rule
Description
Responding to broadcast (ICMP) echoes facilitates network mapping and provides a vector for amplification attacks.
- ID
- SV-258887r991589_rule
- Version
- PHTN-40-000224
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Navigate to and open:
/etc/sysctl.d/zz-stig-hardening.conf
Add or update the following line: