UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The system must not respond to multicast echo requests.


Overview

Finding ID Version Rule ID IA Controls Severity
V-216136 SOL-11.1-050060 SV-216136r959010_rule Low
Description
Multicast echo requests can be useful for reconnaissance of systems and for denial of service attacks.
STIG Date
Solaris 11 X86 Security Technical Implementation Guide 2024-05-30

Details

Check Text ( C-17374r372790_chk )
Determine if response to multicast echo requests is disabled.

# ipadm show-prop -p _respond_to_echo_multicast -co current ipv4
# ipadm show-prop -p _respond_to_echo_multicast -co current ipv6


If the output of all commands is not "0", this is a finding.
Fix Text (F-17372r372791_fix)
The Network Management profile is required.

Disable respond to echo multi-cast for IPv4 and IPv6.

# pfexec ipadm set-prop -p _respond_to_echo_multicast=0 ipv4
# pfexec ipadm set-prop -p _respond_to_echo_multicast=0 ipv6