4.3.2.6 Ensure dpid2 is not in use

Information

This entry starts the dpid2 daemon on system startup. The dpid2 daemon acts as a protocol converter, which enables DPI (SNMP v2) sub-agents, such as hostmibd to talk to a SNMP v1 agent that follows SNMP MUX protocol.

The dpid2 daemon acts as a protocol converter, which enables DPI sub-agents, such as hostmibd to talk to a SNMP v1 agent that follows SNMP MUX protocol. Unless the server hosts an SNMP agent, it is recommended that dpid2 is disabled.

Solution

- On AIX 7.1 and earlier comment out the dpid2 entry in /etc/rc.tcpip and ensure service is stopped:

chrctcp -d dpid2
stopsrc -s dpid2
- On AIX 7.2 and later remove the software:

installp -u bos.net.tcp.snmpd

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 57d73127145be2639618e667cda26889998ae6729e17e382be3a432d3e3ca0e8