Registry Home > Network > Protocols > TCP-IP

Harden the TCP/IP Stack for Denial of Service Attacks (Windows 2000/XP) Popular

Denial of service attacks are network attacks that are aimed at making a computer or a particular service unavailable to network users. These settings can be used to increase the ability for Windows to defend against these attacks when connected directly to the Internet.

This tweak can be easily applied using WinGuides Tweak Manager.
Download a free trial now!

Open your registry and find the key below.

Create the following DWORD values and set them according to the table below.

Restart Windows for the changes to take effect.

Note: These values will not give the best performance due to additional checking and less optimization, but they will provide greater protection against attacks.

Registry Editor Example
|NameTypeData|
|(Default)REG_SZ(value not set)|
|EnableDeadGWDetectREG_DWORD0x00000000 (0)|
|EnableICMPRedirectREG_DWORD0x00000000 (0)|
|EnablePMTUDiscoveryREG_DWORD0x00000000 (0)|
|KeepAliveTimeREG_DWORD0x000493e0 (300000)|
|NoNameReleaseOnDemandREG_DWORD0x00000001 (1)|
|PerformRouterDiscoveryREG_DWORD0x00000000 (0)|
|SynAttackProtectREG_DWORD0x00000002 (2)|
-
|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\P...|
-
Registry Settings
System Key: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
Value Name: EnableDeadGWDetect, EnableICMPRedirect, EnablePMTUDiscovery, KeepAliveTime, NoNameReleaseOnDemand, PerformRouterDiscovery, SynAttackProtect
Data Type: REG_DWORD (DWORD Value)

>> Recommended Download - check, repair and optimize your registry now with Registry Mechanic <<

Disclaimer: Modifying the registry can cause serious problems that may require you to reinstall your operating system. We cannot guarantee that problems resulting from modifications to the registry can be solved. Use the information provided at your own risk.

Last modified: December 19, 2002