i'm just going to copy and paste the relevant section, instead of linking all over.
Code:
3.4.2. icmp_echo_ignore_broadcasts
This variable works precisely the same as icmp_echo_ignore_all except that it will only ignore those ICMP messages sent to broadcast or multicast addresses. It should be quite obvious why this is good, it would among other things stop this specific host from being part of smurf attacks and likely problems. Broadcast pings are generally bad unless you are using this to find out how many hosts on your network(s) are up or not.
The icmp_echo_ignore_broadcasts variable takes a boolean value and is per default turned off. If you want to turn this value on, you should do so since there is relatively few bad sides to not replying to broadcast pings.
Code:
kernel.printk-> stop low-level messages on console
Code:
# Uncomment the next two lines to enable Spoof protection (reverse-path filter)
net.ipv4.conf.default.rp_filter=1
net.ipv4.conf.all.rp_filter=1
Code:
# Uncomment the next line to enable TCP/IP SYN cookies
net.ipv4.tcp_syncookies=1
Code:
# Uncomment the next line to enable packet forwarding for IPv4
net.ipv4.conf.default.forwarding=1
Bookmarks