GEN003601 - TCP backlog queue sizes must be set appropriately.

Information

To provide some mitigation to TCP Denial of Service attacks, the TCP backlog queue sizes must be set to at least 1280 or in accordance with product-specific guidelines.

Solution

Edit /etc/sysctl.conf and add a setting for 'net.ipv4.tcp_max_syn_backlog=1280'.

Procedure:
# sysctl -p

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-218480r603259_rule, STIG-ID|GEN003601, STIG-Legacy|SV-64457, STIG-Legacy|V-23741, Vuln-ID|V-218480

Plugin: Unix

Control ID: 049a2265a6ec7238287ff2ee82d4dd02e092922282f76a188e57b2854c2ab50a