Network: System be configured to prevent ICMP redirects from overriding Open Shortest Path First (OSPF)-generated

20d9022d-7c47-4bd5-9748-c910f27509d0

Allowing ICMP redirect of routes can lead to traffic not being routed properly. When disabled, this forces ICMP to be routed via the shortest path first.

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Administrative Templates
|_ MSS (Legacy)
|_ MSS: (EnableICMPRedirect)
|_ Allow ICMP redirects to override OSPF generated routes to "Disabled".

This policy setting requires the installation of the MSS-Legacy custom template. "MSS-Legacy.admx" and " MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively. Files are available at EventSentry GitHub Repository at: https://github.com/eventsentry/resources

STIG: Server
2022: https://system32.eventsentry.com/stig/viewer/V-254337
2019: https://system32.eventsentry.com/stig/viewer/V-205860
2016: https://system32.eventsentry.com/stig/viewer/V-224918

Desktop
W11: https://system32.eventsentry.com/stig/viewer/V-205860
W10: https://system32.eventsentry.com/stig/viewer/V-220797

NIST 800-53 : CM-6, CM-7, SC-5, SI-4
NIST 800-171: 3.4.6, 3.13.1
CMMC v2.0 L2: CM.L2-3.4.6, SC.L2-3.13.1
PCI-DSS v4.0: 2.2.1
HIPAA SR : ยง164.312(e)(1)
HIPAA HICP : Practice 6 (Network Management)