WA000-WI6022 IIS6 - The maximum number of requests an application pool can process must be set.

Information

A worker process handles all application execution, including authentication and authorization, as well as ISAPI filter and extension loading. This executable process is called W3WP.exe. When acting as the worker process manager, the www service is responsible for controlling the lifetime of all worker processes that are processing requests. The management console allows it to configure options, such as when to start or recycle a worker process, how many requests to serve before recycling, and what to do if the worker becomes blocked or unable to continue processing requests.

Solution

1. Open the IIS Manager > Right click on the desired Application Pool > Select Properties > Select the Recycling tab.
2. Ensure the Recycle worker processes (number of requests) is enabled and the value is set to 35000 or less.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, Rule-ID|SV-38132r2_rule, STIG-ID|WA000-WI6022_IIS6, Vuln-ID|V-13705

Plugin: Windows

Control ID: bbc9145c96d456267139f4412e6de3d35ab428eb5aea5977b470761c29b9bba2