Security considerations for using Bootstrap Protocol server

Bootstrap Protocol (BOOTP) provides a dynamic method for associating workstations with servers and assigning workstation IP addresses and initial program load (IPL) sources.

BOOTP is a TCP/IP protocol used to allow a media-less workstation (client) to request a file containing initial code from a server on the network. The BOOTP server listens on the well known BOOTP server port 67. When a client request is received, the server looks up the IP address defined for the client and returns a reply to the client with the client’s IP address and the name of the load file. The client then initiates a TFTP request to the server for the load file. The mapping between the client hardware address and IP address is kept in the BOOTP table on the system.