Forum Discussion
IP-Source Routing Enabled - Vulnerability
Hey guys... Are we vulnerable at all to this?
https://www.rapid7.com/db/vulnerabilities/generic-ip-source-routing-enabled
- IP Source Routing Enabled Source routing is a feature of the IP protocol which allows the sender of a packet to specify which route the packet should take on the way to its destination (and on the way back). Source routing was originally designed to be used when a host did not have proper default routes in its routing table. However, source routing is rarely used for legitimate purposes nowadays. Attackers can abuse source routing to bypass firewalls or to map your network.
Trying to figure if that is in our fastL4 profiles in terms of making sure that someone cannot broadcast a pre-defined route through any Layer 3 policy, like ip-forwarding.
- Chris_Grant
Employee
https://support.f5.com/csp/article/K10191
The BigIP will drop any packet that arrives with IP Options unless you have explicitly enabled them:
The IP drop counter increments when a packet contains an IP option. If the TM.AcceptIPOptions BigDB key is set to enable, the system accept IPv4 packets with IP options.
So unless you explicitly tell the BigIP otherwise it will not accept packets that use Source Routing. Fastl4 does not change this.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com