3.3.14 sockthresh

Information

The sockthresh parameter value determines what percentage of the total memory allocated to networking, set via thewall, can be used for sockets.

Rationale:

The sockthresh parameterwill be set to 60. This means that 60% of network memory can be used to service new socket connections, the remaining 40% is reserved for existing sockets. This ensures a quality of service for existing connections.

Solution

In /etc/tunables/nextboot, add the sockthresh entry:

no -p -o sockthresh=60

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

N/A

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: f90707f51b29051d91f90eadc8c367a1f355b4e1d2d5eba6a963d5a88f47ef89