2.1.3 Ensure dhcp server services are not in use
Audit#
Run the following commands to verify isc-dhcp-server is not installed:
Nothing should be returned.- OR - - IF - the package is required for dependencies: Run the following command to verify isc-dhcp-server.service and isc-dhcp-server6.service are not enabled:
# systemctl is-enabled isc-dhcp-server.service isc-dhcp-server6.service 2>/dev/null | grep 'enabled'
Run the following command to verify isc-dhcp-server.service and isc-dhcp-server6.service are not active:
Nothing should be returned.Note: If the package is required for a dependency - Ensure the dependent package is approved by local site policy - Ensure stopping and masking the service and/or socket meets local site policy
Remediation#
Run the following commands to stop isc-dhcp-server.service and isc-dhcp-server6.service and remove the isc-dhcp-server package:
- OR - - IF - the isc-dhcp-server package is required as a dependency: Run the following commands to stop and mask isc-dhcp-server.service and isc-dhcp-server6.service: