NET0745 - The network element must have the Maintenance Operation Protocol (MOP) service disabled.

Information

The Maintenance Operations Protocol (MOP) was developed by Digital Equipment Corporation to be used for remote communications. Cisco IOS software routers implement MOP to gather configuration information when communicating with DECNet networks. By default, MOP is enabled on all Ethernet, FastEthernet, and GigabitEthernet interfaces, and disabled on all other type of interfaces. The MOP RC data is carried directly over L2 frames, with no L3 addressing at all, so any RC session is limited to devices that are either on the same physical network segment or in separate network segments that are bridged. It is possible to connect to a Cisco IOS device using a MOP RC client and, with a valid set of credentials, establish an interactive remote session.

Since this is a Cisco default setting, it will not display in the configuration when enabled. The MOP service must be disabled on each interface by using the ;no mop enabled; interface configuration command.

Solution

Configure the device to disable Maintenance Operation Protocol (MOP). Issue the following command on all Ethernet, FastEthernet, and GigabitEthernet interfaces:
(config-if) no mop enable

Not all releases of Cisco IOS support this capability and this does not apply to Cisco NX OS. Document the IOS release and feature set; if the device IOS does not support Maintenance Operation Protocol, no configuration change is necessary.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000381, Rule-ID|SV-79295r1_rule, STIG-ID|NET0745, Vuln-ID|V-64805

Plugin: Cisco

Control ID: f83a1ccb2e528fc2136e72c36e45b59b74d977ed8b700bba54e6a411a45c7710