How to Disable the Hidden ‘Avahi’ Daemon to Improve Ubuntu Security

What is the Avahi Daemon?

In Ubuntu Linux, the avahi-daemon is a background service that implements Apple’s Zeroconf architecture (commonly known as Bonjour). Its primary job is to automatically discover devices and services on your local network, such as shared network printers, Apple TVs, or other computers offering file sharing.

While convenient for a home desktop, running Avahi on a public-facing Ubuntu Server or a machine prioritizing security is unnecessary and creates an open port (UDP 5353). Disabling it reduces your system’s attack surface and saves a small amount of RAM.

How to Disable the Avahi Daemon in Ubuntu

You can safely stop and disable the service using the systemctl command in the terminal.

  1. Open your Ubuntu Terminal (shortcut: Ctrl + Alt + T).
  2. First, stop the daemon from running currently by executing the following command:
sudo systemctl stop avahi-daemon.service
  1. Next, disable the daemon so it does not automatically start the next time you boot your computer:
sudo systemctl disable avahi-daemon.service
  1. Avahi also relies on a secondary socket service. To ensure it is completely deactivated, you must also stop and disable the socket:
sudo systemctl stop avahi-daemon.socket
sudo systemctl disable avahi-daemon.socket

Verifying the Changes

To confirm that Avahi is completely disabled and not listening on your network, run:

sudo systemctl status avahi-daemon.service

The output should clearly state that the service is “inactive (dead).” By disabling Avahi, your Ubuntu system will no longer broadcast its presence or actively listen for zero-configuration services on your local network.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.