2.2.3 Restrict NTP server to loopback interface - restrict lo

Information

Mobile workstations on untrusted networks should not have open listening services
available to other nodes on the network.

Solution

Perform the following to implement the prescribed state -
1. Run the following command in Terminal-sudo vim /etc/ntp-restrict.conf
2. Add the following lines to the filerestrict lo interface ignore wildcard interface listen lo

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(13)

Plugin: Unix

Control ID: 855f47d7f8e20514ba9583a43d918ec6708a117bba6f3105653e4bc46c6854d2