CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 - Control 3.3.1
Description
The net.ipv4.ip_forward and net.ipv6.conf.all.forwarding flags are used to tell the system whether it can forward packets or not.
Rationale
Setting the flags to 0 ensures that a system with multiple interfaces (for example, a hard proxy), will never be able to forward packets, and therefore, never serve as a router.
Impact
None.
Audit Procedure
Command Line
Run the following script to verify IP forwarding is disabled:
#!/usr/bin/bash
{
l_output="" l_output2=""
a_parlist=("net.ipv4.ip_forward=0" "net.ipv6.conf.all.forwarding=0")
l_ufwscf="$([ -f /etc/default/ufw ] && awk -F= '/^\s*IPT_SYSCTL=/ {print $2}' /etc/default/ufw)"
kernel_parameter_chk() {
l_krp="$(sysctl "$l_kpname" | awk -F= '{print $2}' | xargs)"
if [ "$l_krp" = "$l_kpvalue" ]; then
l_output="$l_output\n - \"$l_kpname\" is correctly set to \"$l_krp\" in the running configuration"
else
l_output2="$l_output2\n - \"$l_kpname\" is incorrectly set to \"$l_krp\" in the running configuration and should have a value of: \"$l_kpvalue\""
fi
}
for l_kpe in "${a_parlist[@]}"; do
l_kpname="$(awk -F= '{print $1}' <<< "$l_kpe")"
l_kpvalue="$(awk -F= '{print $2}' <<< "$l_kpe")"
kernel_parameter_chk
done
if [ -z "$l_output2" ]; then
echo -e "\n- Audit Result:\n ** PASS **\n$l_output\n"
else
echo -e "\n- Audit Result:\n ** FAIL **\n - Reason(s) for audit failure:\n$l_output2\n"
[ -n "$l_output" ] && echo -e "\n- Correctly set:\n$l_output\n"
fi
}
Expected Result
- Audit Result:
** PASS **
- "net.ipv4.ip_forward" is correctly set to "0" in the running configuration
- "net.ipv6.conf.all.forwarding" is correctly set to "0" in the running configuration
Remediation
Command Line
Set the following parameters in /etc/sysctl.conf or a /etc/sysctl.d/* file:
net.ipv4.ip_forward = 0
net.ipv6.conf.all.forwarding = 0
Run the following commands to set the active kernel parameters:
sysctl -w net.ipv4.ip_forward=0
sysctl -w net.ipv6.conf.all.forwarding=0
sysctl -w net.ipv4.route.flush=1
sysctl -w net.ipv6.route.flush=1
Default Value
net.ipv4.ip_forward = 0, net.ipv6.conf.all.forwarding = 0
References
- NIST SP 800-53 Rev. 5: CM-7, SC-5, SC-7
- CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0
CIS Controls
Version 8
4.1 Establish and Maintain a Secure Configuration Process - Establish and maintain a secure configuration process for enterprise assets.
Version 7
5.1 Establish Secure Configurations - Maintain documented, standard security configuration standards for all authorized operating systems and software.
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Assessment Status
Automated