STIGQter STIGQter: STIG Summary: A10 Networks ADC ALG Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The A10 Networks ADC must protect against TCP SYN floods by using TCP SYN Cookies.

DISA Rule

SV-237063r639636_rule

Vulnerability Number

V-237063

Group Title

SRG-NET-000512-ALG-000062

Rule Version

AADC-AG-000156

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The following command enables hardware-based SYN cookies:
syn-cookie on-threshold [num] off-threshold [num]

Note: Hardware-based SYN cookies are available only on some models. If the "on-threshold" and "off-threshold" options are omitted, SYN cookies are enabled and are always on regardless of the number of half-open TCP connections.

Check Contents

Review the device configuration.

The following command displays the device configuration and filters the output on the string "syn-cookie":

show run | inc syn-cookie

If SYN cookies are not enabled, this is a finding.

Vulnerability Number

V-237063

Documentable

False

Rule Version

AADC-AG-000156

Severity Override Guidance

Review the device configuration.

The following command displays the device configuration and filters the output on the string "syn-cookie":

show run | inc syn-cookie

If SYN cookies are not enabled, this is a finding.

Check Content Reference

M

Target Key

5285

Comments