3.16 Set Maximum Number of Incoming Connections

Information

This setting controls the maximum number of incoming connections that can be accepted on a TCP port.

Rationale:

Note that the value of 1024 is a minimum to establish a good security posture for this setting. In environments where connection numbers are high, such as a busy webserver, this value may need to be increased.

Solution

To enforce this setting, run the following command:

# ipadm set-prop -p _conn_req_max_q=1024 tcp

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: d4a877dad87c5735965b4fd3b4b255abd4b1a801c4f9f3d9251063f7de747f7c