Remediate the vulnerability that permits Traceroute probes
Applicable scenario
- Product:
ZCF - Component:
Cloud - Version:
4.8.x - Deployment topology: dual management nodes
- Trigger: A vulnerability scan reports that
Tracerouteprobes are permitted and host-side rules are required to restrict related ICMP probe traffic.
Symptoms
- A vulnerability scan reports a risk that permits
Tracerouteprobes. - Only authorized network segments must be allowed; specified ICMP traffic from other sources must be blocked.
- The change applies only to physical-host firewall rules.
Determination method
- Confirm the allowed network segment list before the change.
Sign in to view the rest of this article, plus more troubleshooting and solution know-how.
Sign in