2.2.3 Restrict NTP server to loopback interface - interface listen lo

Information

Mobile workstations on untrusted networks should not have open listening services
available to other nodes on the network.

Solution

Perform the following to implement the prescribed state -
1. Run the following command in Terminal-sudo vim /etc/ntp-restrict.conf
2. Add the following lines to the filerestrict lo interface ignore wildcard interface listen lo

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(13)

Plugin: Unix

Control ID: 855f47d7f8e20514ba9583a43d918ec6708a117bba6f3105653e4bc46c6854d2