SV-237063r639636_rule
V-237063
SRG-NET-000512-ALG-000062
AADC-AG-000156
CAT II
10
The following command enables hardware-based SYN cookies:
syn-cookie on-threshold [num] off-threshold [num]
Note: Hardware-based SYN cookies are available only on some models. If the "on-threshold" and "off-threshold" options are omitted, SYN cookies are enabled and are always on regardless of the number of half-open TCP connections.
Review the device configuration.
The following command displays the device configuration and filters the output on the string "syn-cookie":
show run | inc syn-cookie
If SYN cookies are not enabled, this is a finding.
V-237063
False
AADC-AG-000156
Review the device configuration.
The following command displays the device configuration and filters the output on the string "syn-cookie":
show run | inc syn-cookie
If SYN cookies are not enabled, this is a finding.
M
5285