3.156 - IPv6 TCP data retransmissions must be configured to prevent resources from becoming exhausted.

Information

Configuring Windows to limit the number of times that IPv6 TCP retransmits unacknowledged data segments before aborting the attempt helps prevent resources from becoming exhausted.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)' to '3' or less.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_MS_V1R33_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CAT|III, CCI|CCI-002385, CSCv6|9, CSCv6|9.2, Rule-ID|SV-32450r2_rule, STIG-ID|3.156, Vuln-ID|V-21956

Plugin: Windows

Control ID: 9e56520de6b76921268826bca4b4c604a5463381b74a4ac69d26abe42b455df0