1.1.1.2.1.81 Set 'MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)' to 'Disabled'

Information

This entry appears as MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS) in the SCE. When dead gateway detection is enabled, the IP may change to a backup gateway if a number of connections experience difficulty. Not applicable to Windows Vista or Windows Server 2008. An attacker could force the server to switch gateways, potentially to an unintended one. This would be very difficult to do, so the value of this entry is small.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 0.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\MSS- (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Impact- If you configure this value to 0, Windows cannot detect dead gateways and automatically switch to alternates.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CCE|CCE-2919-9, CSCv6|9.2

Plugin: Windows

Control ID: 8f08f546d4ef5695bb375f7e1eb887495ff01dea1fdb74e5c556422e6726f08d