RE: TCP/IP Stack Hardening

From: dave kleiman (dave_at_isecureu.com)
Date: 12/23/03

  • Next message: Frank Knobbe: "RE: TCP/IP Stack Hardening"
    To: <focus-ms@securityfocus.com>
    Date: Mon, 22 Dec 2003 19:31:36 -0500
    
    

    Frank,

    That statement is somewhat correct. PMTU discovery only affects packets
    outside your local subnet, therefore "should" not affect your internal
    network performance.

    Secondly if you set the PMTU Discovery to 0, and a host route is added to
    the Windows 2000 routing table via an ICMP redirect from the default
    gateway, that host route will not be removed.

    So, by NOT following your recommendation for PMTU Discovery, you
    inadvertently fix your problem caused by NO ICMP redirect.

    I of course originally stated that these hardening guidelines be used for
    systems in your DMZ, not your internal network.

     
    _______________________________
    Dave Kleiman, CISSP, MCSE, CIFI
    dave@isecureu.com
    www.SecurityBreachResponse.com

    "High achievement always takes place in the framework of high expectation."
    Jack Kinder

     

    -----Original Message-----
    From: Frank Knobbe [mailto:frank@knobbe.us]
    Sent: Friday, December 19, 2003 23:29
    To: Hoffmann, Aran
    Cc: focus-ms@securityfocus.com
    Subject: RE: TCP/IP Stack Hardening

    On Fri, 2003-12-19 at 14:12, Hoffmann, Aran wrote:
    > I used to work in a data center with high security requirements and we
    > applied all the referenced tcp/ip hardening to our Win2k servers. The
    > results? Crappy network performance and file transfer timeouts but boy
    > were we secure. As soon as we removed the hardening the network
    > performance problems went away.

    lol.... yeah, the common hardening guidelines contain at least two issues
    that cripple performance.

    1) PMTU discovery: The recommendation is to turn it off since attackers may
    be able to degrade your systems performance by spoofing ICMP "need frag"
    packets. So the recommendation is to cripple the performance yourself!
    Disabling PMTU discovery reduces ALL packets to 576 bytes or so (OTOH). That
    means a lot of small packets within your network. For performance it is
    better to leave PMTUD enabled and start off with packets of a whopping 1500
    bytes (and reduce them if needed).

    2) Disable ICMP Redirect: In larger networks (well... at least network with
    two different gateways) this is a shot in the foot. Most of the time you
    direct traffic to your default gateway (e.g. WAN router), but may need to
    redirect traffic to a different gateway (e.g. Internet firewall). This one
    is noticed pretty quick though. It should be set in environments where only
    one gateway is present (for example, disable ICMP Redirects on systems in
    the DMZ, but leave it enabled your internal systems).

    Source routing should be disabled of course and the backlog stuff should be
    adjusted. I wonder about the usefulness of some of the other settings though
    (like no-name-release-on-demand).

    Oh, and the previous list did not include the TTL. I recommend changing the
    TTL some something odd, like 97 or so. Just to confuse any script-kiddie :)

    Cheers,
    Frank

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Frank Knobbe: "RE: TCP/IP Stack Hardening"

    Relevant Pages

    • Re: Linux als Router
      ... # Enter all trusted network interfaces here. ... # which should be available to the internet and set FW_ROUTE to yes. ... space separated list of ports, ... # Packets to silently reject without log message. ...
      (de.comp.os.unix.linux.misc)
    • Re: Ethernet issue: works one way but not another
      ... packets transmitted, 5 packets received, 0% packet loss ... (This is when connected directly to internet through ... FBSD, I have been working with BSDI at the isp I work for for the last ... As for my network topology, I have an internal network that goes ...
      (freebsd-questions)
    • Re: Weird net connection problem
      ... across the Internet) to throttle or not the traffic). ... Depends how many packets in your connection are lost. ... you connect to some ISP via a router (not a home ADSL one, I should add, ... be advertising to the rest of the Internet, the address of your network, ...
      (uk.comp.sys.mac)
    • RE: unusual 1.11.0.0/16 outbound traffic
      ... "The last 10 years of Internet usage has disproven ... We have been seeing an increasing amount of unusual network activity ... The activity began 2004-08-10 with 4 machines trying to send packets out ... No packets with "data" appear to be making it out. ...
      (Incidents)
    • drone armies C&C report - July/2005
      ... 3356 LEVEL3 Level 3 Communications ... 3491 BTN-ASN - Beyond The Network A ... 3801 MISNET - Mikrotec Internet Ser ... 15857 DIALOG-AS DIALOG-NET Autonomuo ...
      (Bugtraq)