It was depreciated and long ago:
" ..The following commands are no longer used to configure the firewall: sysopt route dnat, sysopt security fragguard, fragguard, and session enable.
The sysopt route dnat command is ignored, starting in PIX Firewall software Version 6.2. Instead, overlapping configurations (network addresses and routes) are automatically handled by outside NAT. .."
from Cisco PIX Firewall Command Reference, Version 6.3
http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/intro.html
Regarding the second question - hardening against what ?
More info would help.