The Arista router must be configured to have Internet Control Message Protocol (ICMP) redirects disabled on all external interfaces.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-256034 | SRG-NET-000362-RTR-000115 | ARST-RT-000550 | SV-256034r882444_rule | 2025-02-20 | 2 |
Description |
---|
The ICMP supports IP traffic by relaying information about paths, routes, and network conditions. Routers automatically send ICMP messages under a wide variety of conditions. Redirect ICMP messages are commonly used by attackers for network mapping and diagnosis. |
ℹ️ Check |
---|
Review the device configuration to determine if controls have been defined to ensure the router does not send ICMP Redirect messages out to any external interfaces. Step 1: To verify the ACL is configured to determine the router does not send ICMP Redirect messages out to any external interfaces, execute the command "sh ip access-list". ip access-group DENY_REDIRECT deny icmp any any redirect permit ip any any Step 2: To verify the ACL is applied outbound on interface, execute the command "sh run int Eth YY". interface Ethernet 2 ip access-group DENY_REDIRECT out If ICMP Redirect messages are enabled on any external interfaces, this is a finding. |
✔️ Fix |
---|
Step 1: Disable ICMP redirects on all external interfaces. ip access-group DENY_REDIRECT deny icmp any any redirect permit ip any any Step 2: Apply the ACL outbound on interfaces. interface Ethernet 2 description EXTERNAL INTERFACE ip access-group DENY_REDIRECT in |