4.2.6 ipignoreredirects

Information

The ipignoreredirects parameter determines whether or not the system will process IP redirects.

Rationale:

The ipignoreredirects will be set to 1, to prevent IP re-directs being processed by the system.

Solution

In /etc/tunables/nextboot, add the ipignoreredirects entry:

no -p -o ipignoreredirects=1

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

0

See Also

https://workbench.cisecurity.org/benchmarks/7851