5.2.18 Ensure sshd MaxStartups is configured

Information

The MaxStartups parameter specifies the maximum number of concurrent unauthenticated connections to the SSH daemon.

More information about the openSSH server configuration is available in the "Configure SSH Server" section overview.

To protect a system from denial of service due to a large number of pending authentication connection attempts, use the rate limiting function of MaxStartups to protect availability of sshd logins and prevent overwhelming the daemon.

Solution

Edit the /etc/ssh/sshd_config file to set the MaxStartups parameter to 10:30:60 or more restrictive as follows:

MaxStartups 10:30:60

See Also

https://workbench.cisecurity.org/benchmarks/25279

Item Details

Category: CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|IA-5

Plugin: Unix

Control ID: e4f988f515b33efe8b549c180fefb71e168d9949bd5ec4c9872794f92c496da0