Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-254034 | JUEX-RT-000620 | SV-254034r844135_rule | Medium |
Description |
---|
The ICMP supports IP traffic by relaying information about paths, routes, and network conditions. Routers automatically send ICMP messages under a wide variety of conditions. Host unreachable ICMP messages are commonly used by attackers for network mapping and diagnosis. |
STIG | Date |
---|---|
Juniper EX Series Switches Router Security Technical Implementation Guide | 2024-06-10 |
Check Text ( C-57486r844133_chk ) |
---|
Review the device configuration to determine if controls have been defined to ensure the router does not send ICMP unreachable notifications out to any external interfaces. [edit policy-options] prefix-list router-address-ipv4 { } [edit firewall family inet] filter term 1 { from { source-prefix-list { router-address-ipv4; } protocol icmp; icmp-type unreachable; } then { log; syslog; discard; } } term default { then { log; syslog; discard; } } } [edit interfaces] unit family inet { filter { output } address } } } Note: Some Juniper devices support both monolithic filters and filter lists. Filter lists separate each term, or set of terms, into a separate filter that is applied sequentially to an interface. If using filter lists, the keywords "input" or "output" change to "input-list" or "output-list". Verify the final list item is a deny-all filter. The deny-all filter is created once per family and can be reused across multiple lists. For example: input-list [ permit_mgt permit_routing_protocols default-deny ]; If ICMP unreachable notifications are enabled on any external interfaces, this is a finding. |
Fix Text (F-57437r844134_fix) |
---|
Disable ICMP unreachable notifications on all external interfaces. set policy-options prefix-list router-addresses-ipv4 set policy-options prefix-list router-addresses-ipv4 set firewall family inet filter set firewall family inet filter set firewall family inet filter set firewall family inet filter set firewall family inet filter set firewall family inet filter set firewall family inet filter set firewall family inet filter set firewall family inet filter set interfaces set interfaces |