SV-223233r513388_rule
V-223233
SRG-APP-000435-NDM-000315
JUSX-DM-000162
CAT II
10
Configure the system and system-options to protect against DoS attacks.
[edit]
set system no-redirects
set system no-ping-record-route
set system no-ping-time-stamp
set system internet-options icmpv4-rate-limit packet-rate 50
set system internet-options icmpv6-rate-limit packet-rate 50
set system internet-options no-ipip-path-mtu-discovery
set system internet-options no-source-quench
set system internet-options tcp-drop-synfin-set
set system internet-options no-ipv6-path-mtu-discovery
set system internet-options no-tcp-reset drop-all-tcp
Verify the system options are configured to protect against DoS attacks.
[edit]
show system
show system internet-options
If the system and system-options which limit the effects of common types of DoS attacks are not configured in compliance with DoD requirements, this is a finding.
V-223233
False
JUSX-DM-000162
Verify the system options are configured to protect against DoS attacks.
[edit]
show system
show system internet-options
If the system and system-options which limit the effects of common types of DoS attacks are not configured in compliance with DoD requirements, this is a finding.
M
4098