AIX7-00-003062 - The ndpd-host daemon must be disabled on AIX.

Information

This is the Neighbor Discovery Protocol (NDP) daemon, required in IPv6.

The ndpd-host is the NDP daemon for the server. Unless the server utilizes IPv6, this is not required and should be disabled to prevent attacks.

Solution

In '/etc/rc.tcpip', comment out the 'ndpd-host' entry by running command:
# chrctcp -d ndpd-host

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-215367r958478_rule, STIG-ID|AIX7-00-003062, STIG-Legacy|SV-101461, STIG-Legacy|V-91363, Vuln-ID|V-215367

Plugin: Unix

Control ID: c5d578f7031fdd21e4c5c753343c3bc3954e1ce89324fce6769d20d13f33937d