SV-237049r639594_rule
V-237049
SRG-NET-000362-ALG-000112
AADC-AG-000099
CAT I
10
The following command configures Source-IP based connection rate limiting:
slb conn-rate-limit src-ip [tcp | udp] conn-limit per [100 | 1000] [exceed-action [log] [lock-out lockout-period]]
Note: Thresholds are specific to the expected traffic for the system or enclave.
Review the device configuration.
The following command displays the device configuration and filters the output on the string "slb conn-rate-limit":
show run | inc slb conn-rate-limit
If Source-IP based connection rate limiting is not configured, this is a finding.
If no lockout period is configured as an action, this is a finding.
V-237049
False
AADC-AG-000099
Review the device configuration.
The following command displays the device configuration and filters the output on the string "slb conn-rate-limit":
show run | inc slb conn-rate-limit
If Source-IP based connection rate limiting is not configured, this is a finding.
If no lockout period is configured as an action, this is a finding.
M
5285