Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DHCP Advertisement

Status
Not open for further replies.

raceman3

Technical User
May 14, 2003
27
US
We recently had our internet router scanned by a network security company and one of the potential security issues they saw was port 67 "dhcp" being advertised. I'm not sure why it is being advertised since I don't have it enabled anywhere in the config and bootp is specifically disabled. Any idea how to eliminate it ?
 
Its not 'advertised' as such - what they mean is they did a port scan on your IP network or IP address (if you have a single device connected such as a firewall etc). When they tried to send a packet to UDP port 67 it was 'open' on your device; i.e. your device is 'listening' on that port. I assume you have a server connected and it is running DHCP but you haven't disabled that service on the ISP facing NIC.

Andy
 
Thanks for the reply, unfortunately a seperate department handles the firewall & servers, is there a way I can tell the router not to respond
 
You could add an ACL to deny access to this (these) ports:

ip access list extended STOP-DHCP
deny udp any any range 67 68
permit ip any any

I would assume thought that you already have an ACL attached to your ISP facing router, in which case you would need to add the deny statement to this ACL.

Andy
 
Did you specifically disable the DHCP service on the router

No Service DHCP.

Its on by defualt.
 
Thanks, that's what I was trying to find. The only DHCP options I was able to locate before was under config ip and there wasn't an option to turn it off. This works
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top