Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
Forces net.ipv4.conf.default.accept_redirects to 0 so every newly created IPv4 interface refuses incoming ICMP redirect messages by default.
Checked against the resolved running state (e.g. sshd -T, sysctl, systemctl show), catches drop-ins and Includes a file read would miss. Caveat: runtime ≠ persistence; a value correct now may not survive a reboot.
Pavois asserts the effective configuration, the live, resolved state, not a file. File-based scanners (OVAL/SCAP, Lynis) miss Includes, drop-ins and runtime defaults; this check sees what is actually applied.
A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.
Why this rule matters
ICMP redirect messages let a router tell a host that a more direct route exists; the host then rewrites its routing table. These messages are unauthenticated, so a forged redirect can silently reroute traffic through an attacker, enabling a man-in-the-middle. The default setting is the template applied to every interface created after it is set, so disabling it (0) ensures new and dynamically added interfaces are protected, not just those present at boot. This feature has few legitimate uses and should be off unless absolutely required.
What Pavois checks
Pavois reads the live runtime value of net.ipv4.conf.default.accept_redirects from the kernel (InSpec kernel_parameter, equivalent to sysctl), not a /etc/sysctl.d/ file. The default key governs interfaces created later, so the running value determines the security posture of future interfaces. A config file might declare 0 while a later drop-in or sysctl -w overrode it; only the effective parameter tells the truth.
describe kernel_parameter('net.ipv4.conf.default.accept_redirects') do
its('value') { should cmp 0 }
end
describe command("grep -hsE '^[[:space:]]*net.ipv4.conf.default.accept_redirects[[:space:]]*=[[:space:]]*0([[:space:]]|$)' /etc/sysctl.conf /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf 2>/dev/null") do
its('stdout') { should match(/\S/) }
endHow to verify it is applied
Run sysctl net.ipv4.conf.default.accept_redirects. Expected output:
net.ipv4.conf.default.accept_redirects = 0
Inspect & investigate
No dedicated log exists. With log_martians enabled, redirect anomalies surface via dmesg | grep -i martian and journalctl -k. Inspect the state with sysctl net.ipv4.conf.default.accept_redirects and all related values with sysctl -a | grep accept_redirects.
Remediation
Pavois's harden plan uses the sysctl resource to set net.ipv4.conf.default.accept_redirects to 0, applying it to the running kernel and persisting it in a Pavois-managed drop-in under /etc/sysctl.d/ so it survives reboot. Apply it with pavois harden apply.
Pavois applies this with its own harden engine, the plan below, not a shell script:
| key | net.ipv4.conf.default.accept_redirects |
|---|---|
| resource | sysctl |
| value | 0 |
pavois harden plan localwhere the target is local, a user@host SSH alias, or a container , Docs
Impact & precautions
Safe for end hosts and ordinary servers, which should never accept ICMP redirects. Note this is the default template and does not retroactively change the all or per-interface values already set; pair it with the matching all.accept_redirects rule for full coverage. The only systems that might rely on accepting redirects are hosts whose gateway uses them to optimise paths, uncommon. No risk of losing remote access from setting this to 0.
Standards mapping
| Standard | Reference | Type | Version | Confidence |
|---|---|---|---|---|
| ANSSI BP-028 | R12 | direct | 2.0 | high |
| CIS | 1.4.3, 3.3.5, 3.3.1.9 | direct | per OS, see the benchmark table | high |
| NIST | 3.1.20, CM-6(a), CM-7(a), CM-7(b), SC-7(a) | supporting | 800-53 Rev 5 · 800-171 Rev 2 (pinned) | medium |
| PCI DSS | 1.4.3 | supporting | 4.0.1 | medium |
Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.