SV-238333r654174_rule
V-238333
SRG-OS-000142-GPOS-00071
UBTU-20-010412
CAT II
10
Configure the Ubuntu operating system to use TCP syncookies by running the following command:
$ sudo sysctl -w net.ipv4.tcp_syncookies=1
If "1" is not the system's default value, add or update the following line in "/etc/sysctl.conf":
net.ipv4.tcp_syncookies = 1
Verify the Ubuntu operating system is configured to use TCP syncookies.
Check the value of TCP syncookies with the following command:
$ sysctl net.ipv4.tcp_syncookies
net.ipv4.tcp_syncookies = 1
If the value is not "1", this is a finding.
Check the saved value of TCP syncookies with the following command:
$ sudo grep -i net.ipv4.tcp_syncookies /etc/sysctl.conf /etc/sysctl.d/* | grep -v '#'
If no output is returned, this is a finding.
V-238333
False
UBTU-20-010412
Verify the Ubuntu operating system is configured to use TCP syncookies.
Check the value of TCP syncookies with the following command:
$ sysctl net.ipv4.tcp_syncookies
net.ipv4.tcp_syncookies = 1
If the value is not "1", this is a finding.
Check the saved value of TCP syncookies with the following command:
$ sudo grep -i net.ipv4.tcp_syncookies /etc/sysctl.conf /etc/sysctl.d/* | grep -v '#'
If no output is returned, this is a finding.
M
5318