SOL-11.1-090280 - The operating system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.


In the case of denial of service attacks, care must be taken when designing the operating system so as to ensure that the operating system makes the best use of system resources.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.


The Network Management profile is required.

Set each link's speed-duplex protection to an appropriate value based on each configured network interface's POSSIBLE settings.

Determine the OS version you are currently securing:

# uname -v

For Solaris 11, 11.1, 11.2, and 11.3:

# pfexec dladm set-linkprop -p en_1000fdx_cap=1 net1

For Solaris 11.4 or newer:

# pfexec dladm set-linkprop -p speed-duplex=1g-f,100m-f net1

See Also

Item Details

References: CAT|II, CCI|CCI-001095, Rule-ID|SV-216237r603268_rule, STIG-ID|SOL-11.1-090280, STIG-Legacy|SV-60771, STIG-Legacy|V-47899, Vuln-ID|V-216237

Plugin: Unix

Control ID: fb02fb40fc5813308a93948c7b7cdbe72f1b6403f49fe1e175500738de51a89a