The system must be configured to prevent IP source routing
hell,
configured the policy.
computer configuration -> windows settings -> security settings -> local policies -> security options -> "mss: (disableipsourcerouting) ip source routing protection level (protects against packet spoofing)" "highest protection, source routing disabled".
but don't know how check functionality of rule. windows protecting "protects against packet spoofing" or not.
hi vijay,
source routing allows computer sends packet specify route packet takes. attackers can use source routed packets obscure identity , location.
if configure setting 0: source routed packets allowed.
if configure setting 1: source routed packets ignored when ip forwarding enabled. if have configured forwarder in environment, packet, source route has been changed forwarder, accepted. , other packet source route has been configured blocked.
if configure setting 2: source routed packets ignored when ip forwarding enabled. packer have configure source route blocked.
best regards,
jay
please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Group Policy
Comments
Post a Comment