3.3.3 Ensure IPv6 is disabled (Not Scored)
Profile Applicability
Level 1 - Server Level 1 - Workstation
Description
Although IPv6 has many advantages over IPv4, few organizations have implemented IPv6.
Rationale
If IPv6 is not to be used, it is recommended that it be disabled to reduce the attack surface of the system.
Audit
Run the following command and verify output includes indicated line:
# modprobe -c | grep ipv6 ... options ipv6 disable=1 ...
Remediation
Create the file /etc/modprobe.d/CIS.conf
and add the following line:
options ipv6 disable=1