diff --git a/README.md b/README.md index 83fa05a..4b0c649 100644 --- a/README.md +++ b/README.md @@ -110,8 +110,8 @@ Networking: - Respond to ARP requests only if the target IP address is on-link, preventing some IP spoofing attacks. -- Optional - Drop gratuitous ARP packets to prevent ARP cache poisoning - via man-in-the-middle and denial-of-service attacks. +- Drop gratuitous ARP packets to prevent ARP cache poisoning via + man-in-the-middle and denial-of-service attacks. - Ignore ICMP echo requests to prevent clock fingerprinting and Smurf attacks. diff --git a/usr/lib/sysctl.d/990-security-misc.conf b/usr/lib/sysctl.d/990-security-misc.conf index 2ac9fca..cc04e0c 100644 --- a/usr/lib/sysctl.d/990-security-misc.conf +++ b/usr/lib/sysctl.d/990-security-misc.conf @@ -482,7 +482,7 @@ net.ipv4.conf.*.arp_ignore=2 ## https://patchwork.ozlabs.org/project/netdev/patch/1428652454-1224-3-git-send-email-johannes@sipsolutions.net/ ## https://www.practicalnetworking.net/series/arp/gratuitous-arp/ ## -#net.ipv4.conf.*.drop_gratuitous_arp=1 +net.ipv4.conf.*.drop_gratuitous_arp=1 ## Ignore ICMP echo requests. ## Prevents clock fingerprinting through ICMP timestamps and Smurf attacks.