RHEL-06-000292 - The DHCP client must be disabled if not needed.

Information

DHCP relies on trusting the local network. If the local network is not trusted, then it should not be used. However, the automatic configuration provided by DHCP is commonly used and the alternative, manual configuration, presents an unacceptable burden in many circumstances.

Solution

For each interface [IFACE] on the system (e.g. eth0), edit '/etc/sysconfig/network-scripts/ifcfg-[IFACE]' and make the following changes.

Correct the BOOTPROTO line to read:

BOOTPROTO=none


Add or correct the following lines, substituting the appropriate values based on your site's addressing scheme:

NETMASK=[local LAN netmask]
IPADDR=[assigned IP address]
GATEWAY=[local LAN default gateway]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-218042r603264_rule, STIG-ID|RHEL-06-000292, STIG-Legacy|SV-50480, STIG-Legacy|V-38679, Vuln-ID|V-218042

Plugin: Unix

Control ID: 332c9f8cfb877d901701bea15a63f217f6a64af95d5e429e11ce2b8797930c96