The IBM z/VM TCP/IP PERSISTCONNECTIONLIMIT statement must be properly configured.
DISA Rule
SV-93605r1_rule
Vulnerability Number
V-78899
Group Title
SRG-OS-000142-GPOS-00071
Rule Version
IBMZ-VM-000730
Severity
CAT II
CCI(s)
- CCI-001095 - The information system manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.
Weight
10
Fix Recommendation
Configure the “PERSISTCONNECTIONLIMIT” statement with a value that is less than the “TCBPOOLSIZE”.
Check Contents
Examine the “TCP/IP” configuration file.
If there is no “PERSISTCONNECTIONLIMIT” statement, this is a finding.
Vulnerability Number
V-78899
Documentable
False
Rule Version
IBMZ-VM-000730
Severity Override Guidance
Examine the “TCP/IP” configuration file.
If there is no “PERSISTCONNECTIONLIMIT” statement, this is a finding.
Check Content Reference
M
Target Key
3211
Comments