SV-234829r622137_rule
V-234829
SRG-OS-000142-GPOS-00071
SLES-15-010310
CAT II
10
Configure the SUSE operating system to use IPv4 TCP syncookies by running the following command as an administrator:
> sudo sysctl -w net.ipv4.tcp_syncookies=1
If "1" is not the system's default value, add or update the following line in "/etc/sysctl.d/99-stig.conf":
> sudo sh -c 'echo "net.ipv4.tcp_syncookies=1" >> /etc/sysctl.d/99-stig.conf'
> sudo sysctl --system
Verify the SUSE operating system is configured to use IPv4 TCP syncookies.
Check to see if syncookies are used with the following command:
> sudo sysctl net.ipv4.tcp_syncookies
net.ipv4.tcp_syncookies = 1
If the network parameter "ipv4.tcp_syncookies" is not equal to "1" or nothing is returned, this is a finding.
V-234829
False
SLES-15-010310
Verify the SUSE operating system is configured to use IPv4 TCP syncookies.
Check to see if syncookies are used with the following command:
> sudo sysctl net.ipv4.tcp_syncookies
net.ipv4.tcp_syncookies = 1
If the network parameter "ipv4.tcp_syncookies" is not equal to "1" or nothing is returned, this is a finding.
M
5274