SOL-11.1-050110 - The system must set maximum number of half-open TCP connections to 4096.

Information

This setting controls how many half-open connections can exist for a TCP port.

It is necessary to control the number of completed connections to the system to provide some protection against denial of service attacks.

Solution

The Network Management profile is required

Configure maximum TCP connections for IPv4 and IPv6.

# pfexec ipadm set-prop -p _conn_req_max_q0=4096 tcp

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-216378r959010_rule, STIG-ID|SOL-11.1-050110, STIG-Legacy|SV-61079, STIG-Legacy|V-48207, Vuln-ID|V-216378

Plugin: Unix

Control ID: 283030323a0ba19ff461890e391bae84ca3eaff45cba209d5b8d28ecc36b23f1