The IBM z/VM TCP/IP PENDINGCONNECTIONLIMIT statement must be properly configured.
DISA Rule
SV-93607r1_rule
Vulnerability Number
V-78901
Group Title
SRG-OS-000142-GPOS-00071
Rule Version
IBMZ-VM-000740
Severity
CAT II
CCI(s)
- CCI-001095 - The information system manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.
Weight
10
Fix Recommendation
Configure the “PENDINGCONNECTIONLIMIT” statement with a value that is less than the “TCBPOOLSIZE”.
Check Contents
Examine the “TCP/IP” configuration file.
If there is no “PENDINGCONNECTIONLIMIT” statement, this is a finding.
Vulnerability Number
V-78901
Documentable
False
Rule Version
IBMZ-VM-000740
Severity Override Guidance
Examine the “TCP/IP” configuration file.
If there is no “PENDINGCONNECTIONLIMIT” statement, this is a finding.
Check Content Reference
M
Target Key
3211
Comments