CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - Control 3.2.1
Description
ICMP Redirects are used to send routing information to other hosts. As a host itself does not act as a router (in a host only configuration), there is no need to send redirects.
Rationale
An attacker could use a compromised host to send invalid ICMP redirects to other router devices in an attempt to corrupt routing and have users access a system set up by the attacker as opposed to a valid system.
Impact
None.
Audit Procedure
Command Line
Run the following commands and verify output matches:
sysctl net.ipv4.conf.all.send_redirects
sysctl net.ipv4.conf.default.send_redirects
grep -E "^\s*net\.ipv4\.conf\.all\.send_redirects" /etc/sysctl.conf /etc/sysctl.d/*
grep -E "^\s*net\.ipv4\.conf\.default\.send_redirects" /etc/sysctl.conf /etc/sysctl.d/*
Expected Result
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
And the grep commands should return:
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects= 0
Remediation
Command Line
Set the following parameters in /etc/sysctl.conf or a /etc/sysctl.d/* file:
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
Run the following commands to set the active kernel parameters:
sysctl -w net.ipv4.conf.all.send_redirects=0
sysctl -w net.ipv4.conf.default.send_redirects=0
sysctl -w net.ipv4.route.flush=1
Default Value
send_redirects is enabled (set to 1) by default.
References
- CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0
CIS Controls
Version 7
5.1 Establish Secure Configurations - Maintain documented, standard security configuration standards for all authorized operating systems and software.
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Assessment Status
Automated