Check: 3.093
Windows 2003 DC STIG:
3.093
(in version v6 r40)
Title
The system must be configured to disable dead gateway detection. (Cat III impact)
Discussion
Dead gateway detection allows switching to a backup gateway if a number of connections to a gateway are experiencing difficulty. An attacker could force internal traffic to be directed to a gateway outside the network if enabled. This setting applies to all network adapters, regardless of their individual settings.
Check Content
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)" to "Disabled".
Additional Identifiers
Rule ID: SV-29607r2_rule
Vulnerability ID: V-4109
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |