WN12-SO-000047 - IPv6 TCP data retransmissions must be configured to prevent resources from becoming exhausted.

Information

Configuring Windows to limit the number of times that IPv6 TCP retransmits unacknowledged data segments before aborting the attempt helps prevent resources from becoming exhausted.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)' to '3' or less.

(See 'Updating the Windows Security Options File' in the STIG Overview document if MSS settings are not visible in the system's policy tools.)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R4_STIG.zip

Item Details

References: CAT|III, CCI|CCI-002385, Rule-ID|SV-226311r794564_rule, STIG-ID|WN12-SO-000047, STIG-Legacy|SV-53181, STIG-Legacy|V-21956, Vuln-ID|V-226311

Plugin: Windows

Control ID: 10d0cc5315ed6146e773aea4dd88998785e5afac0a870f62ccfc3e1f71788892