Forum Discussion

cjbarr1234's avatar
cjbarr1234
Icon for Altostratus rankAltostratus
Apr 27, 2017

IP-Source Routing Enabled - Vulnerability

Hey guys... Are we vulnerable at all to this?

 

https://www.rapid7.com/db/vulnerabilities/generic-ip-source-routing-enabled

 

  1. IP Source Routing Enabled Source routing is a feature of the IP protocol which allows the sender of a packet to specify which route the packet should take on the way to its destination (and on the way back). Source routing was originally designed to be used when a host did not have proper default routes in its routing table. However, source routing is rarely used for legitimate purposes nowadays. Attackers can abuse source routing to bypass firewalls or to map your network.

Trying to figure if that is in our fastL4 profiles in terms of making sure that someone cannot broadcast a pre-defined route through any Layer 3 policy, like ip-forwarding.

 

  • https://support.f5.com/csp/article/K10191

     

    The BigIP will drop any packet that arrives with IP Options unless you have explicitly enabled them:

     

    The IP drop counter increments when a packet contains an IP option. If the TM.AcceptIPOptions BigDB key is set to enable, the system accept IPv4 packets with IP options.

     

    So unless you explicitly tell the BigIP otherwise it will not accept packets that use Source Routing. Fastl4 does not change this.