3.6.4 TCP/IP Tuning - ipsrcroutesend

Information

The ipsrcroutesend parameter determines whether or not the system can send source-routed packets.

The ipsrcroutesend parameter will be set to 0, to ensure that any local applications cannot send source routed packets.

Solution

In /etc/tunables/nextboot, add the ipsrcroutesend entry-

no -p -o ipsrcroutesend=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot.

See Also

https://workbench.cisecurity.org/files/528