2.2.6 Ensure 'Send connector timeout' is set to '10'

Information

This parameter controls the number of idle minutes before the connection to the Send connector is dropped, even if data is being actively transmitted.

Note: The ConnectionTimeout parameter must be higher than the ConnectionInactivityTimeout parameter.

Rationale:

Connections may suffer from delays in message transfer once established. In order to allow new connections to be established, the timeout period should be reduced so that connections are not maintained for unnecessary periods of time.

Impact:

Valid connections could be dropped.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-SendConnector -Identity <'IdentityName'> -ConnectionInactivityTimeOut 00:10:00

Default Value:

00:10:00 (10 minutes)

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-10

Plugin: Windows

Control ID: a697c76b103dcaa3235af7fd2807b4916aabacf15c2f5977e4b37720bffffe88