GEN003601 - TCP backlog queue sizes must be set appropriately.

Information

To provide some mitigation to TCP Denial of Service attacks, the TCP backlog queue sizes must be set to at least 1280 or in accordance with product-specific guidelines.

Solution

Edit /etc/sysctl.conf and add a setting for "net.ipv4.tcp_max_syn_backlog=1280".

Procedure:
# sysctl -p

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-23741, Rule-ID|SV-37594r2_rule, STIG-ID|GEN003601, Vuln-ID|V-23741

Plugin: Unix

Control ID: b07adf7751243168f1ae261d6d781036dfaa333f8698f5b654b04066569eafaf