Click here to get back home

MSS tcp registry values in windwos 2003 server security guide

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
MSS tcp registry values in windwos 2003 server security guide rand007 08-21-2006
Posted by rand007 on August 21, 2006, 2:33 am
Please log in for more thread options
Hi,

I am currently hardening windows 2003 server SP1 O.S according to
"windows
server 2003 security guide" (version 2.1).

I noticed that there are some "MSS:" registry values that do not exist
in
this guide and existed in the previous version, such as:
1. "MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock
applications (recommended)" and all other "AFD" settings.
2. "MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size
(possible DoS by an attacker using a small MTU)".
3. "MSS: (TCPMaxPortsExhausted) How many dropped connect requests to
initiate SYN attack protection (5 is recommended)".

All these settings look important (at leat to me).

Does anyone know the reason these setting do not exist anymore in the
new
security guide?

--
RanD


Posted by Roger Abell [MVP] on August 25, 2006, 12:19 am
Please log in for more thread options
I keep meaning to find "previous version" to compare and see whether
you mean v1.0 of the 2k3, or you mean the 2k guide.
I know the stack had work, and that a couple those settings can be
performance intense.


> Hi,
>
> I am currently hardening windows 2003 server SP1 O.S according to
> "windows
> server 2003 security guide" (version 2.1).
>
> I noticed that there are some "MSS:" registry values that do not exist
> in
> this guide and existed in the previous version, such as:
> 1. "MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock
> applications (recommended)" and all other "AFD" settings.
> 2. "MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size
> (possible DoS by an attacker using a small MTU)".
> 3. "MSS: (TCPMaxPortsExhausted) How many dropped connect requests to
> initiate SYN attack protection (5 is recommended)".
>
> All these settings look important (at leat to me).
>
> Does anyone know the reason these setting do not exist anymore in the
> new
> security guide?
>
> --
> RanD
>



Similar ThreadsPosted
MSS tcp registry values in windows 2003 server security guide August 20, 2006, 7:23 am
Windows Server 2003 Security Guide 2.0 January 17, 2006, 10:24 am
Windows Server 2003 Security Guide for SP2? June 4, 2007, 7:03 pm
Role-based security from Windows Server 2003 Security Guide gives problems November 6, 2006, 8:00 am
Windows Server 2003 Security Guide: International versions? October 23, 2007, 1:51 pm
2003 Security Guide August 10, 2005, 12:30 pm
Server refreshes its security policy with wrong values July 9, 2006, 8:29 am
Help: How to extract registry data from dead server HDD... October 5, 2005, 2:00 pm
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm
2003 IIS/OS Server Security May 16, 2006, 9:13 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap