2.1.4 Set 'no service dhcp' - dhcp pool

Information

Disable the Dynamic Host Configuration Protocol (DHCP) server and relay agent features on your router.

Rationale:

The DHCP server supplies automatic configuration parameters, such as dynamic IP address, to requesting systems. A dedicated server located in a secured management zone should be used to provide DHCP services instead. Attackers can potentially be used for denial-of-service (DoS) attacks.

Impact:

To reduce the risk of unauthorized access, organizations should implement a security policy restricting network protocols and explicitly require disabling all insecure or unnecessary protocols such as the Dynamic Host Configuration Protocol (DHCP).

Solution

Disable the DHCP server.

hostname(config)#<strong>no service dhcp</strong>

Default Value:

Enabled by default, but also requires a DHCP pool to be set to activate the DHCP server.

See Also

https://workbench.cisecurity.org/benchmarks/9270

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: e390a5267b384ea62e858ad59cc8540b5e9e7fa78740d758390e350cb4b0f9a0