STIGQter STIGQter: STIG Summary: IBM z/VM Using CA VM:Secure Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 27 Apr 2018:

The IBM z/VM TCP/IP FOREIGNIPCONLIMIT statement must be properly configured.

DISA Rule

SV-93603r1_rule

Vulnerability Number

V-78897

Group Title

SRG-OS-000142-GPOS-00071

Rule Version

IBMZ-VM-000720

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the “FOREIGNIPCONLIMIT” statement with a value specifying the maximum number of connections that a foreign IP address is allowed to have open at the same time.

The System Administrator should determine the proper value.

Check Contents

Examine “TCP/IP” configuration file.

If there is no “FOREIGNIPCONLIMIT” statement, this is a finding.

If the “FOREIGNIPCONLIMIT” has a value of “0”, this is a finding.

Vulnerability Number

V-78897

Documentable

False

Rule Version

IBMZ-VM-000720

Severity Override Guidance

Examine “TCP/IP” configuration file.

If there is no “FOREIGNIPCONLIMIT” statement, this is a finding.

If the “FOREIGNIPCONLIMIT” has a value of “0”, this is a finding.

Check Content Reference

M

Target Key

3211

Comments