VCRP-67-000001 - The rhttpproxy must drop connections to disconnected clients.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The rhttpproxy client connections that are established but no longer connected can consume resources that might otherwise be required by active connections. It is a best practice to terminate connections that are no longer connected to an active client.

Solution

Navigate to and open /etc/vmware-rhttpproxy/config.xml.

Locate the <config>/<vmacore>/<tcpKeepAlive>/<clientSocket> block and configure <idleTimeSec> as follows:

<idleTimeSec>900</idleTimeSec>

Restart the service for changes to take effect.

# vmon-cli --restart rhttpproxy

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y22M10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000054, Rule-ID|SV-240716r679661_rule, STIG-ID|VCRP-67-000001, Vuln-ID|V-240716

Plugin: Unix

Control ID: c4cede4b57a8f38ce06a690af0cad0c9f737a510dfff16b929e6022dbfb0c50d