rp_filter
Submitted by admin on Tue, 2006-07-18 23:38
- 0 - No source validation.
- 1 - Do source validation by reversed path, as specified in RFC1812. Recommended option for single homed hosts and stub network routers. Could cause troubles for complicated (not loop free) networks running a slow unreliable protocol (sort of RIP), or using static routes.
conf/all/rp_filter must also be set to 1 to do source validation on the interface.
If you set this to 1 on a router that is the only connection for a network to the net, it will prevent spoofing attacks against your internal networks (external addresses can still be spoofed), without the need for additional firewall rules.
The default value is 0, but note that some distributions enable it in startup scripts.
»
- Add new comment
- 4929 reads








Recent comments
3 weeks 6 days ago
3 weeks 6 days ago
5 weeks 4 days ago
9 weeks 4 days ago
11 weeks 4 days ago
11 weeks 4 days ago
11 weeks 4 days ago
12 weeks 1 day ago
15 weeks 4 days ago
16 weeks 5 days ago