18.5.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Peer Name Resolution Protocol (PNRP) allows for distributed resolution of a name to an IPv6 address and port number.

The protocol operates in the context of _clouds_.

A cloud is a set of peer computers that can communicate with each other by using the same IPv6 scope.

Peer-to-Peer protocols allow for applications in the areas of RTC, collaboration, content distribution and distributed processing.

The recommended state for this setting is: 'Enabled'.

Rationale:

This setting enhances the security of the environment and reduces the overall risk exposure related to peer-to-peer networking.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':


Computer Configuration\Policies\Administrative Templates\Network\Microsoft Peer-to-Peer Networking Services\Turn off Microsoft Peer-to-Peer Networking Services


Note: This Group Policy path is provided by the Group Policy template 'P2P-pnrp.admx/adml' that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

Microsoft Peer-to-Peer Networking Services are turned off in their entirety, and all applications dependent on them will stop working.

See Also

https://workbench.cisecurity.org/files/1933

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CCE|CCE-33208-0, CSCv6|9.1

Plugin: Windows

Control ID: 0666e0fc0d9cf17c7e8c3d572316ceaf4872bf895d6dbeead7f0ae3756644cb9