The system must be configured to prevent IP source routing


hell,

configured the policy. 

computer configuration -> windows settings -> security settings -> local policies -> security options -> "mss: (disableipsourcerouting) ip source routing protection level (protects against packet spoofing)" "highest protection, source routing disabled".

but  don't know how check functionality of rule. windows  protecting "protects against packet spoofing" or not.


hi vijay,

source routing allows computer sends packet specify route packet takes. attackers can use source routed packets obscure identity , location.

if configure setting 0: source routed packets allowed.

if configure setting 1: source routed packets ignored when ip forwarding enabled. if have configured forwarder in environment, packet, source route has been changed forwarder, accepted. , other packet source route has been configured blocked.

if configure setting 2: source routed packets ignored when ip forwarding enabled. packer have configure source route blocked.

best regards,

jay


please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...