2.2.5 Ensure DHCP Server is not enabled - 'isc-dhcp-server6'

Information

The Dynamic Host Configuration Protocol (DHCP) is a service that allows machines to be dynamically assigned IP addresses. Unless a system is specifically set up to act as a DHCP server, it is recommended that this service be deleted to reduce the potential attack surface.

Solution

Run the following commands to disable dhcpd: # systemctl disable isc-dhcp-server# systemctl disable isc-dhcp-server6

See Also

https://workbench.cisecurity.org/files/1866

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 3fe08595b8935448816cab65f82c2d3f68a6cf7b16e999e9e1a22430367bb934