18.4.11 Ensure 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'

Information

This setting controls the number of times that TCP retransmits an individual data segment (non-connect segment) before the connection is aborted. The retransmission time-out is doubled with each successive retransmission on a connection. It is reset when responses resume. The base time-out value is dynamically determined by the measured round-trip time on the connection.

Solution

Make sure 'MSS: (TcpMaxDataRetransmissions)' is Enabled and set to 3.

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CCE|CCE-36051-1, CSCv6|9

Plugin: Windows

Control ID: 15849f74e0f876d25a1fd7b91e6574fb90bfae2bdc70d7bf8a863ac23c5df146