Set net.ipv4.conf.*.shared_media=0

This commit is contained in:
raja-grewal 2024-12-19 10:29:56 +00:00 committed by GitHub
parent 95b535764c
commit 750367a906
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 3 additions and 3 deletions

View File

@ -102,8 +102,8 @@ Networking:
- Disable ICMP redirect acceptance and redirect sending messages to prevent
man-in-the-middle attacks and minimize information disclosure.
- Optional - Deny sending and receiving shared media redirects to reduce
the risk of IP spoofing attacks.
- Deny sending and receiving shared media redirects to reduce the risk of IP
spoofing attacks.
- Optional - Enable ARP filtering to mitigate some ARP spoofing and ARP
cache poisoning attacks.

View File

@ -451,7 +451,7 @@ net.ipv6.conf.*.accept_redirects=0
## https://datatracker.ietf.org/doc/html/rfc1620
## https://www.frozentux.net/ipsysctl-tutorial/chunkyhtml/theconfvariables.html
##
#net.ipv4.conf.*.shared_media=0
net.ipv4.conf.*.shared_media=0
## Enable ARP (Address Resolution Protocol) filtering.
## Prevents the Linux kernel from handling the ARP table globally