NET0960 - TCP intercept features must be provided by the network device - policer burst-size-limit

Information

The TCP SYN attack involves transmitting a volume of connections that cannot be completed at the destination. This attack causes the connection queues to fill up, thereby denying service to legitimate TCP users.

Solution

Configure the device to use TCP Intercept to protect against TCP SYN attacks from outside the network.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-6, CAT|II, Rule-ID|SV-16144r3_rule, STIG-ID|NET0960, Vuln-ID|V-3165

Plugin: Juniper

Control ID: afc3a592b88091f026a1d773bfbc21000c08d114fa41215944430220ae642cd5