← All rules
SOCLE-CLD-SYS-027// Kernel & network (sysctl)mediumeffective runtime

Drop Gratuitous ARP frames on All IPv4 Interfaces

Sets net.ipv4.conf.all.drop_gratuitous_arp=1 so the kernel ignores unsolicited ARP announcements used for cache poisoning.

Checked against the resolved running state (e.g. sshd -T, sysctl, systemctl show), catches drop-ins and Includes a file read would miss. Caveat: runtime ≠ persistence; a value correct now may not survive a reboot.

A pass proves✓ running now✓ on disk✓ survives rebootthe qualified verdict →
Debian 12CIS 1.1.0Debian 13CIS 1.0.0FedoraRHEL 10 / Rocky 10 / AlmaLinux 10RHEL 8 / Rocky 8 / AlmaLinux 8CIS 4.0.0RHEL 9 / Rocky 9 / AlmaLinux 9CIS 2.0.0Ubuntu 22.04CIS 3.0.0Ubuntu 24.04CIS 1.0.0Ubuntu 26.04
One check, maps to 1 standard

Pavois asserts the effective configuration, the live, resolved state, not a file. File-based scanners (OVAL/SCAP, Lynis) miss Includes, drop-ins and runtime defaults; this check sees what is actually applied.

A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.

Why this rule matters

Gratuitous ARP frames are unsolicited ARP announcements ("this IP is now at this MAC") that a host broadcasts without anyone asking. Because ARP is unauthenticated, an attacker can flood the segment with forged gratuitous ARP to poison neighbors' ARP caches and redirect their traffic to themselves, the core technique of ARP-spoofing man-in-the-middle attacks. Setting net.ipv4.conf.all.drop_gratuitous_arp=1 makes the kernel ignore these unsolicited announcements, neutralizing this poisoning vector. Legitimate use of gratuitous ARP (e.g. failover IP takeover) is the main thing to weigh against it.

What Pavois checks

Pavois reads the live kernel value via kernel_parameter('net.ipv4.conf.all.drop_gratuitous_arp') and asserts it equals 1. Whether gratuitous ARP is actually dropped depends on the running kernel value, not on a config file: a sysctl.d entry written but not reloaded, or overridden by a per-interface key, would leave the host still accepting poison frames. Reading the effective value is the only proof the protection is live.

describe kernel_parameter('net.ipv4.conf.all.drop_gratuitous_arp') do
  its('value') { should cmp 1 }
end
describe command("grep -hsE '^[[:space:]]*net.ipv4.conf.all.drop_gratuitous_arp[[:space:]]*=[[:space:]]*1([[:space:]]|$)' /etc/sysctl.conf /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf 2>/dev/null") do
  its('stdout') { should match(/\S/) }
end

How to verify it is applied

Run sysctl net.ipv4.conf.all.drop_gratuitous_arp. Expected output:

net.ipv4.conf.all.drop_gratuitous_arp = 1

Inspect & investigate

  • sysctl net.ipv4.conf.all.drop_gratuitous_arp shows the current value.
  • cat /proc/sys/net/ipv4/conf/all/drop_gratuitous_arp is the raw kernel value.
  • Inspect the resolved ARP/neighbor table with ip neigh show to spot poisoning attempts (a known IP suddenly mapped to a new MAC). Use sysctl -a | grep drop_gratuitous_arp to see all and per-interface values.

Remediation

Pavois's harden plan uses the sysctl resource to set net.ipv4.conf.all.drop_gratuitous_arp to 1. It writes the key into a Pavois-managed drop-in and reloads it so unsolicited ARP frames are dropped immediately and after reboot. Apply it with pavois harden apply.

Pavois applies this with its own harden engine, the plan below, not a shell script:

keynet.ipv4.conf.all.drop_gratuitous_arp
resourcesysctl
value1
pavois harden plan local

where the target is local, a user@host SSH alias, or a container , Docs

Impact & precautions

The key caveat is IP failover and high availability: keepalived/VRRP, Pacemaker, cloud floating IPs and live-migration all rely on gratuitous ARP to tell the network that a virtual IP has moved to a new MAC. With drop_gratuitous_arp=1, neighbors may not learn the new owner quickly, causing traffic black-holing after a failover. Before applying, exclude hosts that depend on gratuitous-ARP-driven IP takeover, or accept that failover convergence may require an explicit ARP refresh. On a plain single-IP server there is no functional impact and no lockout risk.

Standards mapping

StandardReferenceTypeVersionConfidence
ANSSI BP-028R12direct2.0high

Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.

Sources & references