MSS policy: "MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)". Controls whether the TCP/IP stack processes source-routed IPv4 packets, which attackers can use to obscure their identity or route packets through unintended paths. Registry: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters:DisableIPSourceRouting (REG_DWORD). CIS Benchmark (L1) and DISA STIG recommend value 2 (highest protection). Reference: Policy CSP - MSSLegacy (IPv4SourceRoutingProtectionLevel)
Values
| Enum Value | Description |
|---|---|
|
|
Enabled: no additional protection (registry value 0). Source-routed packets are forwarded as normal. No protection against packet spoofing via source routing. |
|
|
Enabled: source-routed packets ignored when IP forwarding is enabled (registry value 1). Partial protection — source routing packets are dropped only when IP forwarding is active. |
|
|
Enabled: highest protection — source routing completely disabled (registry value 2). All incoming source-routed packets are dropped regardless of IP forwarding state. Recommended by CIS and DISA STIG. |
|
|
Source routing protection is disabled by policy (policy not configured). |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"ENABLED_NO_ADDITIONAL_PROTECTION"