| Net device
| Parameter
| Default value
| Suggested value
| Comment
|
| /dev/ip | ip_check_subnet_addr
| 1
| 0
| Permit 0 in local network part (should be the default)
|
| /dev/ip
| ip_forward_directed_broadcasts
| 1
| 0
| Don't forward directed broadcasts
|
| /dev/ip
| ip_forward_src_routed
| 1
| 0
| Don't forward packets with source route options
|
| /dev/ip
| ip_forwarding
| 2
| 0
| Disable IP forwarding
|
| /dev/ip
| ip_ire_gw_probe
| 1
| 0
| Disable dead gateway detection (currently no ndd help text; echo-requests interact badly with firewalls)
|
| /dev/ip
| ip_pmtu_strategy
| 2
| 1
| Don't use echo-request PMTU strategy (can be used for amplification attacks and we don't want to send echo-requests anyway)
|
| /dev/ip
| ip_respond_to_address_mask_broadcast
| 0
| 0
| Don't respond to ICMP address mask request broadcasts
|
| /dev/ip
| ip_respond_to_echo_broadcast
| 1
| 0
| Don't respond to ICMP echo request broadcasts
|
| /dev/ip
| ip_respond_to_timestamp
| 0
| 0
| Don't respond to ICMP timestamp requests
|
| /dev/ip
| ip_respond_to_timestamp_broadcast
| 0
| 0
| Don't respond to ICMP timestamp request broadcasts
|
| /dev/ip
| ip_send_redirects
| 1
| 0
| Don't send ICMP redirect messages (if we have no need to send redirects)
|
| /dev/ip
| ip_send_source_quench
| 1
| 0
| Don't send ICMP source quench messages (deprecated)
|
| /dev/tcp
| tcp_conn_request_max
| 20
| 500
| Increase TCP listen queue maximum (performance)
|
| /dev/tcp
| tcp_syn_rcvd_max
| 500
| 500
| HP SYN flood defense
|
| /dev/tcp
| tcp_text_in_resets
| 1
| 0
| Don't send text messages in TCP RST segments (should be the default)
|