SV-242660r714290_rule
V-242660
SRG-APP-000435-NDM-000315
CSCO-NM-000550
CAT II
10
Configure the system and system-options to protect against DoS attacks. These are examples of setting that should be adjusted to limit DoS attacks. The exact values will vary based on site traffic.
Use the synflood-limit to configure a TCP SYN packet rate limit.
To configure the limit of TCP/UDP/ICMP packets from a source IP address, use the rate-limit command in configuration mode.
Verify the system and system-options are configured to protect against DoS attacks.
If the system and system-options that limit the effects of common types of DoS attacks are not configured in compliance with DoD requirements, this is a finding.
V-242660
False
CSCO-NM-000550
Verify the system and system-options are configured to protect against DoS attacks.
If the system and system-options that limit the effects of common types of DoS attacks are not configured in compliance with DoD requirements, this is a finding.
M
5384