4.5.16 Ensure tcp_pmtu_discover is disabled

Information

The tcp_pmtu_discover parameter controls whether TCP MTU discovery is enabled.

The tcp_pmtu_discover parameter will be set to 0 . The idea of MTU discovery is to avoid packet fragmentation between remote networks. This is achieved by discovering the network route and utilizing the smallest MTU size within that path when transmitting packets. When tcp_pmtu_discover is enabled, it has the potential to disrupt network availability.

Solution

Run the following command to set the tcp_pmtu_discover entry:

no -p -o tcp_pmtu_discover=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 495bbeb7ef4837456d3407d45fe7197eb85d58533fb71cfb2282621fab5bdfbd