2.1.3 Ensure discard services are not enabled - discard-dgram

Information

Disabling this service will reduce the remote attack surface of the system.

Solution

Run the following commands to disable discard-dgram and discard-stream - # chkconfig discard-dgram off
# chkconfig discard-stream off

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_Amazon_Linux_Benchmark_v2.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Unix

Control ID: 0c41d00f564b313dfdd383abdaaa914d3e84d789db0ac52d76fd9d5f27fe36ab