Focus on Microsoft
RE: TCP/IP Stack Hardening Dec 19 2003 08:12PM
Hoffmann, Aran (AHoffmann cta net) (3 replies)
RE: TCP/IP Stack Hardening Dec 21 2003 06:54AM
dave kleiman (dave isecureu com)
RE: TCP/IP Stack Hardening Dec 20 2003 04:29AM
Frank Knobbe (frank knobbe us) (1 replies)
RE: TCP/IP Stack Hardening Dec 23 2003 12:31AM
dave kleiman (dave isecureu com) (1 replies)
RE: TCP/IP Stack Hardening Dec 23 2003 04:20AM
Frank Knobbe (frank knobbe us) (1 replies)
RE: TCP/IP Stack Hardening Dec 23 2003 04:37AM
dave kleiman (dave isecureu com)
Re: TCP/IP Stack Hardening Dec 19 2003 11:11PM
Tod Beardsley (todb planb-security net)
Hoffmann, Aran wrote:

> The results? Crappy network performance and file transfer timeouts
> but boy were we secure. As soon as we removed the hardening the
> network performance problems went away.

Systematic troubleshooting would have likely solved your timeout
problems. The majority of these keys won't have a lot of / any impact
on normal network performance, all things being equal. Incidentally,
changing some key defaults will not only quote-secure-unquote your
stack, but will also stymie pretty much every TCP-based OS
profiler/fingerprinter around. Which is cool.

--
"It's okay to yell 'fire' in a crowded theater
if the theater is actually on fire."
Tod Beardsley | www.planb-security.net

------------------------------------------------------------------------
---
------------------------------------------------------------------------
---

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus