From 8cf5ed990a3940c108d661c6c169b5720b1459d1 Mon Sep 17 00:00:00 2001 From: Patrick Schleizer Date: Thu, 5 Dec 2019 15:52:24 -0500 Subject: [PATCH] comment --- etc/sysctl.d/tcp_hardening.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/etc/sysctl.d/tcp_hardening.conf b/etc/sysctl.d/tcp_hardening.conf index 7174c2d..85b6ddf 100644 --- a/etc/sysctl.d/tcp_hardening.conf +++ b/etc/sysctl.d/tcp_hardening.conf @@ -35,6 +35,7 @@ net.ipv4.conf.default.accept_source_route=0 ## Enable reverse path filtering to prevent IP spoofing and ## mitigate vulnerabilities such as CVE-2019-14899. +## https://forums.whonix.org/t/enable-reverse-path-filtering/8594 net.ipv4.conf.default.rp_filter=1 net.ipv4.conf.all.rp_filter=1