<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DISA STIG NET0965 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212598#M53760</link>
    <description>&lt;P&gt;I have a 4270-20 (7.1(7)E4) monitoring a network that is required to use the DISA STIGs for certain security settings. there is a requirement (STIG ID NET0965) that requires the following:&lt;/P&gt;&lt;P&gt;The network device must be configured with a maximum wait time of 10 seconds or less to allow a host to establish a TCP connection.&lt;/P&gt;&lt;P&gt;Configure the maximum wait time for TCP connections to be established with the device to 10 seconds or less.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is possible on a router or switch but can this be configured on the IPS?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:58:04 GMT</pubDate>
    <dc:creator>joedansereau</dc:creator>
    <dc:date>2019-03-10T12:58:04Z</dc:date>
    <item>
      <title>DISA STIG NET0965</title>
      <link>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212598#M53760</link>
      <description>&lt;P&gt;I have a 4270-20 (7.1(7)E4) monitoring a network that is required to use the DISA STIGs for certain security settings. there is a requirement (STIG ID NET0965) that requires the following:&lt;/P&gt;&lt;P&gt;The network device must be configured with a maximum wait time of 10 seconds or less to allow a host to establish a TCP connection.&lt;/P&gt;&lt;P&gt;Configure the maximum wait time for TCP connections to be established with the device to 10 seconds or less.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is possible on a router or switch but can this be configured on the IPS?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212598#M53760</guid>
      <dc:creator>joedansereau</dc:creator>
      <dc:date>2019-03-10T12:58:04Z</dc:date>
    </item>
    <item>
      <title>DISA STIG NET0965</title>
      <link>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212599#M53761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I don't have an answer for you, but would like to share your pain.&amp;nbsp; I wish DISA would spend the time to document this stuff on the most common platforms for the benefit of the people that are having to implement.&amp;nbsp; Would save a lot of people a lot of time from having to scour the Internet looking for this information.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 23:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212599#M53761</guid>
      <dc:creator>efairbanks</dc:creator>
      <dc:date>2013-06-04T23:47:46Z</dc:date>
    </item>
    <item>
      <title>DISA STIG NET0965</title>
      <link>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212600#M53762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Perhaps more to the point, when will Cisco submit their IDS/IPS products for JITC testing for inclusion on the DOD UC APL?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jun 2013 20:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212600#M53762</guid>
      <dc:creator>mark.barrett</dc:creator>
      <dc:date>2013-06-07T20:23:12Z</dc:date>
    </item>
    <item>
      <title>Still nothing from Cisco,</title>
      <link>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212601#M53763</link>
      <description>&lt;P&gt;Still nothing from Cisco, issue still applicable on 4200 series appliances running 7.1(9)E4. Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2014 13:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212601#M53763</guid>
      <dc:creator>joedansereau</dc:creator>
      <dc:date>2014-10-29T13:43:09Z</dc:date>
    </item>
    <item>
      <title>from Cisco support:</title>
      <link>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212602#M53764</link>
      <description>&lt;P&gt;from Cisco support:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE&gt;
&lt;STRONG&gt;IPS Signatures&lt;/STRONG&gt;&lt;/PRE&gt;

&lt;PRE&gt;
&lt;STRONG&gt;Half-open SYN Attack&lt;/STRONG&gt;&lt;/PRE&gt;

&lt;PRE&gt;

&amp;nbsp;&lt;/PRE&gt;

&lt;PRE&gt;
&lt;A href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=3050&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S774"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=3050&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S774&lt;/A&gt;&lt;/PRE&gt;

&lt;PRE&gt;

&amp;nbsp;&lt;/PRE&gt;

&lt;PRE&gt;

&amp;nbsp;&lt;/PRE&gt;

&lt;PRE&gt;
&lt;STRONG&gt;IPS Signatures&lt;/STRONG&gt;&lt;/PRE&gt;

&lt;PRE&gt;
&lt;STRONG&gt;TCP Session Embryonic Timeout&lt;/STRONG&gt;&lt;/PRE&gt;

&lt;PRE&gt;

&amp;nbsp;&lt;/PRE&gt;

&lt;PRE&gt;
&lt;A href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=1302&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S212"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=1302&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S212&lt;/A&gt;&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from STIG writer:&lt;/P&gt;
&lt;P&gt;NET0965 allows the use of filtering thresholds or timeout periods to drop half-open TCP connections.&amp;nbsp; Using a TCP half-open SYN signature to trigger rate-limiting or blocking meets the first of the two options.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2015 17:18:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disa-stig-net0965/m-p/2212602#M53764</guid>
      <dc:creator>joedansereau</dc:creator>
      <dc:date>2015-01-06T17:18:31Z</dc:date>
    </item>
  </channel>
</rss>

