4.5.18 Ensure udp_pmtu_discover is disabled

Information

The udp_pmtu_discover parameter controls whether MTU discovery is enabled.

The udp_pmtu_discover parameter will be set to 0 . The idea of MTU discovery is to avoid packet fragmentation between remote networks. This is achieved by discovering the network route and utilizing the smallest MTU size within that path when transmitting packets. When udp_pmtu_discover is enabled, it has the potential to disrupt network availability.

Solution

Run the following command to set the udp_pmtu_discover entry:

no -p -o udp_pmtu_discover=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 108532ebb137a0d9de6c4eff0e1af98115d20f6aa8889cb51b689867de8b7ff4