diff --git a/RHEL/6/input/auxiliary/stig_overlay.xml b/RHEL/6/input/auxiliary/stig_overlay.xml index 5570050c326f..34fca6dc4b25 100644 --- a/RHEL/6/input/auxiliary/stig_overlay.xml +++ b/RHEL/6/input/auxiliary/stig_overlay.xml @@ -256,7 +256,7 @@ The system must not send ICMPv4 redirects by default. - + The system must not send ICMPv4 redirects from any interface. @@ -316,7 +316,7 @@ The IPv6 protocol handler must not be bound to the network stack unless needed. - + The system must ignore ICMPv6 redirects by default. diff --git a/RHEL/6/input/auxiliary/transition_notes.xml b/RHEL/6/input/auxiliary/transition_notes.xml index 4339ced6b015..d581d39397ce 100644 --- a/RHEL/6/input/auxiliary/transition_notes.xml +++ b/RHEL/6/input/auxiliary/transition_notes.xml @@ -1615,7 +1615,7 @@ sysctl_net_ipv4_conf_default_accept_redirects rule. Check does exist in the RHEL6 prose, it can be automated and OVAL for it does exist. -rule=sysctl_ipv4_all_send_redirects manual=no +rule=sysctl_net_ipv4_conf_all_send_redirects manual=no This check is split in the RHEL6 prose into the above and the sysctl_net_ipv4_conf_default_send_redirects rule. diff --git a/RHEL/6/input/profiles/C2S.xml b/RHEL/6/input/profiles/C2S.xml index 729bc5a4079f..6283021a67fc 100644 --- a/RHEL/6/input/profiles/C2S.xml +++ b/RHEL/6/input/profiles/C2S.xml @@ -290,7 +290,7 @@ baseline. + + + @@ -217,7 +217,7 @@ + - + @@ -90,7 +90,7 @@ + diff --git a/RHEL/6/input/profiles/fisma-medium-rhel6-server.xml b/RHEL/6/input/profiles/fisma-medium-rhel6-server.xml index 48dc10092f4d..431545223c65 100644 --- a/RHEL/6/input/profiles/fisma-medium-rhel6-server.xml +++ b/RHEL/6/input/profiles/fisma-medium-rhel6-server.xml @@ -252,7 +252,7 @@ + @@ -269,7 +269,7 @@ + diff --git a/RHEL/6/input/profiles/nist-CL-IL-AL.xml b/RHEL/6/input/profiles/nist-CL-IL-AL.xml index 51c207b581b9..3c176b79e997 100644 --- a/RHEL/6/input/profiles/nist-CL-IL-AL.xml +++ b/RHEL/6/input/profiles/nist-CL-IL-AL.xml @@ -301,7 +301,7 @@ assurance." + @@ -311,7 +311,7 @@ assurance." + diff --git a/RHEL/6/input/profiles/usgcb-rhel6-server.xml b/RHEL/6/input/profiles/usgcb-rhel6-server.xml index b7d0b3802377..533c221b60b7 100644 --- a/RHEL/6/input/profiles/usgcb-rhel6-server.xml +++ b/RHEL/6/input/profiles/usgcb-rhel6-server.xml @@ -116,7 +116,7 @@ + + diff --git a/RHEL/6/input/system/network/ipv6.xml b/RHEL/6/input/system/network/ipv6.xml index cf9a07fc912e..bf1e4f442c60 100644 --- a/RHEL/6/input/system/network/ipv6.xml +++ b/RHEL/6/input/system/network/ipv6.xml @@ -138,7 +138,7 @@ An illicit router advertisement message could result in a man-in-the-middle atta - + Disable Accepting IPv6 Redirects diff --git a/RHEL/6/input/system/network/kernel.xml b/RHEL/6/input/system/network/kernel.xml index 05756bed3683..7bef59199450 100644 --- a/RHEL/6/input/system/network/kernel.xml +++ b/RHEL/6/input/system/network/kernel.xml @@ -28,7 +28,7 @@ only appropriate for systems acting as routers. - + Disable Kernel Parameter for Sending ICMP Redirects for All Interfaces