3.1.3 Check Responses TTL Field - check-response-ttl=yes

Information

Avahi can be configured to ignore packets unless the TTL field is 255.

Rationale:

Setting this field makes sure that only multicast DNS packets from the local network are processed. Although a properly configured router and firewall should not allow these packets from outside networks, this is an extra check to ensure this does not happen.

Solution

Edit the /etc/avahi/avahi-daemon.conf file and add the following line to the [server] section:

check-response-ttl=yes

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 7830e3748a7b9749a867194d59f23e61f370295bf28771f83d4523b95ccde0ca