3.1.2 Service Only via Required Protocol - use-ipv6=no'

Information

Avahi can support either the IPv4 or IPv6 protocols, depending on what the system is configured to use.

Rationale:

Configure IPv4 or IPv6, depending on which protocol needs to be used. Limiting support to the protocol that is actually reduces the potential attack surface

Solution

Edit the /etc/avahi/avahi-daemon.conf file to use the appropriate protocol for your environment.

if only using IPv4, disable IPv6 with this line:

use-ipv6=no

if only using IPv6, disable IPv4 with this line:

use-ipv4=no

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: aec862f1493785c93fe7eaba0d674f0491e716559120273b75b504c8e3707f29