AlmaLinux OS 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-269248SRG-OS-000480-GPOS-00227ALMA-09-019050SV-269248r1050130_rule2025-02-201
Description
Responding to broadcast (ICMP) echoes facilitates network mapping and provides a vector for amplification attacks. Ignoring ICMP echo requests (pings) sent to broadcast or multicast addresses makes the system slightly more difficult to enumerate on the network.
ℹ️ Check
Verify AlmaLinux OS 9 does not respond to ICMP echoes sent to a broadcast address with the following command: $ sysctl net.ipv4.icmp_echo_ignore_broadcasts net.ipv4.icmp_echo_ignore_broadcasts = 1 If the returned line does not have a value of "1", this is a finding.
✔️ Fix
Configure AlmaLinux OS 9 to use reverse path filtering on all IP interfaces. Create a numbered *.conf file in /etc/sysctl.d/ with the following content: net.ipv4.icmp_echo_ignore_broadcasts = 1 The system configuration files need to be reloaded for the changes to take effect. To reload the contents of the files, run the following command: $ sysctl –system