Skip to content

Commit

Permalink
Add some IPv6 options
Browse files Browse the repository at this point in the history
  • Loading branch information
flawedworld committed Sep 18, 2020
1 parent 944fed3 commit 8f7727e
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions etc/sysctl.d/30_security-misc.conf
Expand Up @@ -82,6 +82,8 @@ net.ipv6.conf.default.accept_redirects=0
## Disables ICMP redirect sending.
net.ipv4.conf.all.send_redirects=0
net.ipv4.conf.default.send_redirects=0
net.ipv6.conf.all.accept_redirects=0
net.ipv6.conf.default.accept_redirects=0

## Ignores ICMP requests.
net.ipv4.icmp_echo_ignore_all=1
Expand All @@ -92,6 +94,8 @@ net.ipv4.tcp_syncookies=1
## Disable source routing.
net.ipv4.conf.all.accept_source_route=0
net.ipv4.conf.default.accept_source_route=0
net.ipv6.conf.all.accept_source_route=0
net.ipv6.conf.default.accept_source_route=0

## Enable reverse path filtering to prevent IP spoofing and
## mitigate vulnerabilities such as CVE-2019-14899.
Expand Down Expand Up @@ -149,3 +153,8 @@ vm.swappiness=1
## Disallow kernel profiling by users without CAP_SYS_ADMIN
## https://www.kernel.org/doc/Documentation/sysctl/kernel.txt
kernel.perf_event_paranoid=3

# Do not accept router advertisments
net.ipv6.conf.all.accept_ra=0
net.ipv6.conf.default.accept_ra=0

0 comments on commit 8f7727e

Please sign in to comment.