47 lines
1.5 KiB
Plaintext
47 lines
1.5 KiB
Plaintext
|
#
|
||
|
# Configuration file for setting network variables. Please note these settings
|
||
|
# override /etc/sysctl.conf and /etc/sysctl.d. If you prefer to use
|
||
|
# /etc/sysctl.conf, please adjust IPT_SYSCTL in /etc/default/ufw. See
|
||
|
# Documentation/networking/ip-sysctl.txt in the kernel source code for more
|
||
|
# information.
|
||
|
#
|
||
|
|
||
|
# Uncomment this to allow this host to route packets between interfaces
|
||
|
net/ipv4/ip_forward=1
|
||
|
#net/ipv6/conf/default/forwarding=1
|
||
|
#net/ipv6/conf/all/forwarding=1
|
||
|
|
||
|
# Disable ICMP redirects. ICMP redirects are rarely used but can be used in
|
||
|
# MITM (man-in-the-middle) attacks. Disabling ICMP may disrupt legitimate
|
||
|
# traffic to those sites.
|
||
|
net/ipv4/conf/all/accept_redirects=0
|
||
|
net/ipv4/conf/default/accept_redirects=0
|
||
|
net/ipv6/conf/all/accept_redirects=0
|
||
|
net/ipv6/conf/default/accept_redirects=0
|
||
|
|
||
|
# Ignore bogus ICMP errors
|
||
|
net/ipv4/icmp_echo_ignore_broadcasts=1
|
||
|
net/ipv4/icmp_ignore_bogus_error_responses=1
|
||
|
net/ipv4/icmp_echo_ignore_all=0
|
||
|
|
||
|
# Don't log Martian Packets (impossible addresses)
|
||
|
# packets
|
||
|
net/ipv4/conf/all/log_martians=0
|
||
|
net/ipv4/conf/default/log_martians=0
|
||
|
|
||
|
#net/ipv4/tcp_fin_timeout=30
|
||
|
#net/ipv4/tcp_keepalive_intvl=1800
|
||
|
|
||
|
# Uncomment this to turn off ipv6 autoconfiguration
|
||
|
#net/ipv6/conf/default/autoconf=1
|
||
|
#net/ipv6/conf/all/autoconf=1
|
||
|
|
||
|
# Uncomment this to enable ipv6 privacy addressing
|
||
|
#net/ipv6/conf/default/use_tempaddr=2
|
||
|
#net/ipv6/conf/all/use_tempaddr=2
|
||
|
|
||
|
# Do not send ICMP redirects (we are not a router)
|
||
|
# Add the following lines
|
||
|
net/ipv4/conf/all/send_redirects=0
|
||
|
net/ipv4/ip_no_pmtu_disc=1
|