AIX7-00-003058 - If AIX server does not host an SNMP agent, the dpid2 daemon must be disabled.

Information

The dpid2 daemon acts as a protocol converter, which enables DPI (SNMP v2) sub-agents, such as hostmibd, to talk to a SNMP v1 agent that follows SNMP MUX protocol.

To prevent attacks this daemon should not be enabled unless there is no alternative.

Solution

In '/etc/rc.tcpip', comment out the 'dpid2' entry by running command:
# chrctcp -d dpid2

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-215364r958478_rule, STIG-ID|AIX7-00-003058, STIG-Legacy|SV-101453, STIG-Legacy|V-91355, Vuln-ID|V-215364

Plugin: Unix

Control ID: 6bd92c5182818cb0ee69fdd31d38904df87b29653fae14b5c73bace08b2826e4