2.1.5 Set 'no ip identd'

Information

Disable the identification (identd) server.

Rationale:

Identification protocol enables identifying a user's transmission control protocol (TCP) session. This information disclosure could potentially provide an attacker with information about users.

Solution

Disable the ident server.

hostname(config)#no ip identd

Impact:

To reduce the risk of unauthorized access, organizations should implement a security policy restricting network protocols and explicitly require disabling all insecure or unnecessary protocols such as the identification protocol (identd).

Default Value:

Disabled by default

References:

http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/Baseline_Security/sec_chap4.html#wp1056539

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Cisco

Control ID: 850d9e6b1bea8937c97a147d6c1ff85e6041885d8f49f0ff7004582fc0a5cb11