4.2.14 sockthresh

Information

The sockthresh parameter value determines what percentage of the total memory allocated to networking, set via thewall, can be used for sockets.

Rationale:

The sockthresh parameterwill be set to 60. This means that 60% of network memory can be used to service new socket connections, the remaining 40% is reserved for existing sockets. This ensures a quality of service for existing connections.

Solution

In /etc/tunables/nextboot, add the sockthresh entry:

no -p -o sockthresh=60

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

N/A

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: 282750ddbcfb7fb8caa64561cd7dd7f0cf98656bbba80afdeb74a0647d48e2d6