3.1.4 Prevent Other Programs from Using Avahi's Port - disallow-other-stacks=yes

Information

Avahi can stop other multicast Domain Name Service (mDNS) stacks from running on the host by preventing other processes from binding to port 5353.

Rationale:

Setting this option ensures that only Avahi is processing multicast DNS packets coming into that port on the system.

Solution

Edit the /etc/avahi/avahi-daemon.conf file and add the following line:

disallow-other-stacks=yes

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 28bfe9cad21dadd96a4bd47eb5c3beac8662d1ba6a4873482498b60a6d7ada50