SonicWALL - Flood Protection - TCP - Max Seg Lifetime

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SonicWALL - Flood Protection - TCP - Maximum Segment Lifetime <= 8 seconds.

Determines the number of seconds that any TCP packet is valid before it expires. This setting is also used to determine the amount of time (calculated as twice the Maximum Segment Lifetime, or 2MSL) that an actively closed TCP connection remains in the TIME_WAIT state to ensure that the proper FIN / ACK exchange has occurred to cleanly close the TCP connection.

Solution

Navigate to Firewall Settings->Flood Protection->TCP Settings and set 'Maximum Segment Lifetime (seconds):' to a value of 8 or less.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, 800-53|SC-10

Plugin: SonicWALL

Control ID: fa0848ac88c5b43b9b50f288fce3271888c274b31b25c26fbeb0c67a9aadbc49