# CIS Ubuntu 14.04 LTS - 3.3.3 Ensure IPv6 is disabled

> Verify that IPv6 is disabled if not required to reduce the attack surface

- Skill: `cyberstrikeus/cis-ubuntu-14-04-lts-3-3-3-ensure-ipv6-is-disabled` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-3-3-3-ensure-ipv6-is-disabled`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu-14-04-lts-3-3-3-ensure-ipv6-is-disabled/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu-14-04-lts-3-3-3-ensure-ipv6-is-disabled

---


# 3.3.3 Ensure IPv6 is disabled (Not Scored)

## Profile Applicability

- Level 1 - Server
- Level 1 - Workstation

## Description

Although IPv6 has many advantages over IPv4, few organizations have implemented IPv6.

## Rationale

If IPv6 is not to be used, it is recommended that it be disabled to reduce the attack surface of the system.

## Audit Procedure

Run the following command and verify that each linux line has the `ipv6.disable=1` parameter set:

```bash
grep "^\s*linux" /boot/grub/grub.cfg
```

## Expected Result

Each linux line should contain `ipv6.disable=1`.

## Remediation

Edit `/etc/default/grub` and add `ipv6.disable=1` to GRUB_CMDLINE_LINUX:

```
GRUB_CMDLINE_LINUX="ipv6.disable=1"
```

Run the following command to update the grub2 configuration:

```bash
update-grub
```

## Default Value

IPv6 is enabled by default.

## References

- CIS Controls: 3 - Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
- CIS Controls: 11 - Secure Configurations for Network Devices such as Firewalls, Routers and switches

## Profile

- Level 1 - Server
- Level 1 - Workstation

