Skip to content

Instantly share code, notes, and snippets.

@octomagon
Last active June 2, 2016 15:28
Show Gist options
  • Select an option

  • Save octomagon/0621ae7dea1711e353be3c6a1db17922 to your computer and use it in GitHub Desktop.

Select an option

Save octomagon/0621ae7dea1711e353be3c6a1db17922 to your computer and use it in GitHub Desktop.
Hardening sysctl.conf
/etc/sysctl.conf hardening
# Uncomment the next two lines to enable Spoof protection (reverse-path filter)
# Turn on Source Address Verification in all interfaces to
# prevent some spoofing attacks
net.ipv4.conf.default.rp_filter=1
net.ipv4.conf.all.rp_filter=1

# Uncomment the next line to enable TCP/IP SYN cookies
# See http://lwn.net/Articles/277146/
# Note: This may impact IPv6 TCP sessions too
net.ipv4.tcp_syncookies=1

# Block SYN attacks
net.ipv4.tcp_max_syn_backlog = 2048
net.ipv4.tcp_synack_retries = 2
net.ipv4.tcp_syn_retries = 5

# Do not accept ICMP redirects (prevent MITM attacks)
net.ipv4.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0

# Log Martian Packets
net.ipv4.conf.all.log_martians = 1
net.ipv4.icmp_ignore_bogus_error_responses = 1
Save the updates
sudo service procps start
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment