3.3.3 Ensure IPv6 is disabled (Not Scored)

Level 1 - Server
Level 1 - Workstation 

Although IPv6 has many advantages over IPv4, few organizations have implemented IPv6.

If IPv6 is not to be used, it is recommended that it be disabled to reduce the attack surface of the system.

Run the following command and verify that each linux line has the ipv6.disable=1 parameter set:

# grep "^\s*linux" /boot/grub/grub.cfg

Edit /etc/default/grub and add ipv6.disable=1 to GRUB_CMDLINE_LINUX:


Run the following command to update the grub2 configuration:

# update-grub
