GEN003601 - TCP backlog queue sizes must be set appropriately - tcp_conn_req_max_q0

Information

To provide some mitigation to TCP DoS attacks, the TCP backlog queue sizes must be set to at least 1280 or in accordance with product-specific guidelines.

Solution

Procedure:
# ndd -set /dev/tcp tcp_conn_req_max_q0 1280
# ndd -set /dev/tcp tcp_conn_req_max_q 1024

Ensure these commands are also present in system startup scripts.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-227794r603266_rule, STIG-ID|GEN003601, STIG-Legacy|SV-28639, STIG-Legacy|V-23741, Vuln-ID|V-227794

Plugin: Unix

Control ID: 2c573f97751bf6e538f189b85315b5ecff389c215b6ca64f846f05e4928a1c0c