Information
Disables the DHCP service
Rationale:
The Firepower can act as a DHCP or DHCP Relay server. However, on untrusted interface, attacker can get the opportunity of the availability of the service to perform DoS attacks such as DHCP starvation that will exhaust not only the IP addresses' space but also the memory and CPU resources of the security appliance and bring it down.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
DHCP Relay can be configured through the Firepower Management Center:
Step 1 - Choose Devices > Device Management, and edit the FTD device.
Step 2 - Select DHCP > DHCP Relay.