58 lines
1.9 KiB
Plaintext
58 lines
1.9 KiB
Plaintext
#
|
|
# Configuration file for setting network variables. Please note these settings
|
|
# override /etc/sysctl.conf. If you prefer to use /etc/sysctl.conf, please
|
|
# adjust IPT_SYSCTL in /etc/default/ufw.
|
|
#
|
|
|
|
# Uncomment this to allow this host to route packets between interfaces
|
|
#net/ipv4/ip_forward=1
|
|
#net/ipv6/conf/default/forwarding=1
|
|
#net/ipv6/conf/all/forwarding=1
|
|
|
|
# Turn on Source Address Verification in all interfaces to prevent some
|
|
# spoofing attacks
|
|
net/ipv4/conf/default/rp_filter=1
|
|
net/ipv4/conf/all/rp_filter=1
|
|
|
|
# Do not accept IP source route packets (we are not a router)
|
|
net/ipv4/conf/default/accept_source_route=0
|
|
net/ipv4/conf/all/accept_source_route=0
|
|
net/ipv6/conf/default/accept_source_route=0
|
|
net/ipv6/conf/all/accept_source_route=0
|
|
|
|
# Disable ICMP redirects. ICMP redirects are rarely used but can be used in
|
|
# MITM (man-in-the-middle) attacks. Disabling ICMP may disrupt legitimate
|
|
# traffic to those sites.
|
|
net/ipv4/conf/default/accept_redirects=0
|
|
net/ipv4/conf/all/accept_redirects=0
|
|
net/ipv6/conf/default/accept_redirects=0
|
|
net/ipv6/conf/all/accept_redirects=0
|
|
|
|
# Ignore bogus ICMP errors
|
|
net/ipv4/icmp_echo_ignore_broadcasts=1
|
|
net/ipv4/icmp_ignore_bogus_error_responses=1
|
|
net/ipv4/icmp_echo_ignore_all=0
|
|
|
|
# Don't log Martian Packets (impossible packets)
|
|
net/ipv4/conf/default/log_martians=0
|
|
net/ipv4/conf/all/log_martians=0
|
|
|
|
# Change to '1' to enable TCP/IP SYN cookies This disables TCP Window Scaling
|
|
# (http://lkml.org/lkml/2008/2/5/167)
|
|
net/ipv4/tcp_syncookies=0
|
|
|
|
#net/ipv4/tcp_fin_timeout=30
|
|
#net/ipv4/tcp_keepalive_intvl=1800
|
|
|
|
# normally allowing tcp_sack is ok, but if going through OpenBSD 3.8 RELEASE or
|
|
# earlier pf firewall, should set this to 0
|
|
net/ipv4/tcp_sack=1
|
|
|
|
# Uncomment this to turn off ipv6 autoconfiguration
|
|
#net/ipv6/conf/default/autoconf=0
|
|
#net/ipv6/conf/all/autoconf=0
|
|
|
|
# Uncomment this to enable ipv6 privacy addressing
|
|
#net/ipv6/conf/default/use_tempaddr=2
|
|
#net/ipv6/conf/all/use_tempaddr=2
|