GEN003601 - TCP backlog queue sizes must be set appropriately - tcp_conn_req_max_q

Information

To provide some mitigation to TCP DoS attacks, the TCP backlog queue sizes must be set to at least 1280 or in accordance with product-specific guidelines.

Solution

Procedure:
# ndd -set /dev/tcp tcp_conn_req_max_q0 1280
# ndd -set /dev/tcp tcp_conn_req_max_q 1024

Ensure these commands are also present in system startup scripts.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-226889r603265_rule, STIG-ID|GEN003601, STIG-Legacy|SV-28639, STIG-Legacy|V-23741, Vuln-ID|V-226889

Plugin: Unix

Control ID: f9db00fc42bdbccb60f13f3aa05595f701a7a9c80ee5a54de26cb42f9aba535b