4.3.2.4 Ensure dhcprd is not in use

Information

This entry starts the dhcprd daemon on system startup. The dhcprd daemon listens for broadcast packets, receives them, and forwards them to the appropriate server.

The dhcprd daemon is the DHCP relay deamon that forwards the DHCP and BOOTP packets in the network. You must disable this service if DHCP is not enabled in the network.

Solution

- On AIX 7.1 and earlier comment out the dhcprd entry in /etc/rc.tcpip and ensure service is stopped:

chrctcp -d dhcprd
stopsrc -s dhcprd
- On AIX 7.2 and later remove the software:

installp -u bos.net.tcp.dhcpd

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 56b4eeb84eeb119c6c37cf50c0c096a944f2d86ec155947e5ded4b22dfed9fe6