Deny Decline Messages
An XCCDF Rule
Description
Edit /etc/dhcp/dhcpd.conf
and add or correct the following
global option to prevent the DHCP server from responding the DHCPDECLINE
messages, if possible:
deny declines;
Rationale
The DHCPDECLINE message can be sent by a DHCP client to indicate that it does not consider the lease offered by the server to be valid. By issuing many DHCPDECLINE messages, a malicious client can exhaust the DHCP server's pool of IP addresses, causing the DHCP server to forget old address allocations.
- ID
- xccdf_org.ssgproject.content_rule_dhcp_server_deny_decline
- Severity
- Unknown
- References
- Updated