2.2.14 Disable Local RPC Port Mapping Service - Make sure that network/rpc/bind is disabled.

Information

Level: 1

Solution

To disable local RPC port mapping service, run the following command-

svcadm disable svc:/network/rpc/bind

If you want to restrict access to this service, but not disable it completely, consider using a host-based firewall such as ipfilter(5) to control what hosts are allowed to access this daemon. Alternatively, TCP Wrappers support can be enabled in the daemon with the commands-

svccfg -s svc:/network/rpc/bind setprop config/enable_tcpwrappers = true

svcadm refresh rpc/bind

See Also

https://benchmarks.cisecurity.org/tools2/solaris/CIS_Oracle_Solaris_10_Benchmark_v5.2.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 464a14820ae4b46a82395b8ce027debf0030f525a1839487f5628444a8a767de