Vendor | Settings |
Cisco | verify unicast
reverse-path no ip directed broadcast |
Windows | HKLM\system\currentcontrolset\services\tcpip\parameters\ TcpTimedWaitDelay - set to - 96 KeepAliveTime - set to - 30000 TcpMaxHalfOpen - set to - 100 TcpMaxPortsExhausted - set to - 1 TcpMaxHalfOpenRetried - set to - 80 TcpMaxDataRetransmissions - set to - 3 TcpMaxConnectResponseRetransmissions - set to - 2 EnableDeadGWDetect - set to - 0 EnablePMTUBHDetect - set to - 0 EnableICMPRedirects - set to - 0 EnableSecurityFilters - set to - 1 DisableIPSourceRouting - set to - 1 SynAttackProtect - set to - 2 HKLM\system\currentcontrolset\services\afd\ DynamicBacklogGrowthDelta - set to - 10 EnableDynamicBacklog - set to - 1 MaximumDynamicBacklog - set to - 2000 MinimumDynamicBacklog - set to - 20 Interfaces\{InterfaceID} PerformRouterDiscovery - set to - 0 |
Linux | Use IPTables - use the -m limit iptables module to limit
connections echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter echo 1 > /proc/sys/net/ipv4/tcp_syncookies echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts echo 120 > /proc/sys/net/ipv4/vs/timeout_synack ##decrease as needed echo 15 > /proc/sys/net/ipv4/vs/timeout_synrecv ##decrease as needed echo 180 > /proc/sys/net/ipv4/tcp_max_syn_backlog ##increase as needed |