How To Harden the TCP/IP Stack Against Denial of Service Attacks in Windows Server 2003Article ID : 324270 Last Review : July 15, 2004 Revision : 9.1 This article was previously published under Q324270For a Microsoft Windows 2000 version of this article, see 315669.
The default TCP/IP stack configuration is tuned to handle standard intranet traffic. If you connect a computer directly to the Internet, Microsoft recommends that you harden the TCP/IP stack against denial of service attacks.
http://support.microsoft.com/default.aspx?scid=kb;en-us;324270
I've attached (below) a REG file that I made that has all the default hardening parameters I would apply for Windows 2000/XP/2003.