1.4.11 Enable Dynamic IP Address Restrictions - Deny By Request Rate

Information

IIS8 introduced the concept of Dynamic IP Address Restrictions which can be used to thwart DDos attacks. This is different than the IP Address Restrictions that can be manually maintained within IIS. The default action Deny action for restrictions is to return a Forbidden response to the client.

Dynamic IP address filtering allows administrators to configure the server to block access for IPs that exceed the specified number of requests. Ensure that you receive the Forbidden page once the block has been enforced.

Solution

1. Open IIS Manager.
2. Open the IP Address and Domain Restrictions feature.
3. Click Edit Dynamic Restrictions Settings..
4. Check the Deny IP Address based on the number of concurrent requests and the Deny IP Address based on the number of requests over a period of time boxes. The values can be tweaked as needed for your specific environment.

Default Value:
By default Dynamic IP Restrictions are not enabled.

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_8_Benchmark_v1.4.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Windows

Control ID: f53539f0b10d19a29a561d88e1e7f3c9290f38954d6cebb8503f6da5e44f731b