From dd65ecf8974789b8be0de8d57ad203fec6ad53a8 Mon Sep 17 00:00:00 2001 From: Tommy Date: Thu, 6 Jun 2024 14:03:28 -0700 Subject: [PATCH] Ignore Bogus ICMP responses --- etc/sysctl.d/99-server.conf | 3 +++ etc/sysctl.d/99-workstation.conf | 3 +++ 2 files changed, 6 insertions(+) diff --git a/etc/sysctl.d/99-server.conf b/etc/sysctl.d/99-server.conf index 8cac0e7..73de4ae 100644 --- a/etc/sysctl.d/99-server.conf +++ b/etc/sysctl.d/99-server.conf @@ -74,6 +74,9 @@ net.ipv4.conf.*.rp_filter = 1 net.ipv4.icmp_echo_ignore_all = 0 net.ipv6.icmp.echo_ignore_all = 0 +# Ignore Bogus ICMP responses +net.ipv4.icmp_ignore_bogus_error_responses = 1 + # Enable IP Forwarding # Almost all of my servers run Docker anyways, and Docker absolutely requires this. net.ipv4.ip_forward = 1 diff --git a/etc/sysctl.d/99-workstation.conf b/etc/sysctl.d/99-workstation.conf index ba47eb6..0eca1c5 100644 --- a/etc/sysctl.d/99-workstation.conf +++ b/etc/sysctl.d/99-workstation.conf @@ -73,6 +73,9 @@ net.ipv4.conf.*.rp_filter = 1 net.ipv4.icmp_echo_ignore_all = 1 net.ipv6.icmp.echo_ignore_all = 1 +# Ignore Bogus ICMP responses +net.ipv4.icmp_ignore_bogus_error_responses = 1 + # Enable IP Forwarding # Needed for VM networking and whatnot. net.ipv4.ip_forward = 1