2.1.3 Set 'no ip bootp server'

Information

Disable the Bootstrap Protocol (BOOTP) service on your routing device.

Rationale:

BootP allows a router to issue IP addresses. This should be disabled unless there is a specific requirement.

Impact:

To reduce the risk of unauthorized access, organizations should implement a security policy restricting network protocols and explicitly require disabling all insecure or unnecessary protocols such as 'ip bootp server'.

Solution

Disable the bootp server.

hostname(config)#ip dhcp bootp ignore

Default Value:

Enabled

See Also

https://workbench.cisecurity.org/benchmarks/12741

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: 5fad1752cfdc09f2b05b2ee8b0cb3d80c4b7d5cf60b275650d7c0bc13064ed25