Utilizar algumas regras no sysctl.conf é uma boa solução para tentar prevenir ataques do tipo spoofing e alguns tipos de DOS.
NOTA: Verifique se eth0 é sua interface primária, caso não seja, mude eth0 para eth1
no SSH, edite o sysctl:
pico -w /etc/sysctl.conf
Você pode simplesmente copiar e subsituir pelo código abaixo :
#Kernel sysctl configuration file for Red Hat Linux # # Para valores binarios 0 desabilita e 1 habilitar. # # # Disables packet forwarding net.ipv4.ip_forward=0 # Disables IP source routing net.ipv4.conf.all.accept_source_route = 0 net.ipv4.conf.lo.accept_source_route = 0 net.ipv4.conf.eth0.accept_source_route = 0 net.ipv4.conf.default.accept_source_route = 0 # Enable IP spoofing protection, turn on source route verification net.ipv4.conf.all.rp_filter = 1 net.ipv4.conf.lo.rp_filter = 1 net.ipv4.conf.eth0.rp_filter = 1 net.ipv4.conf.default.rp_filter = 1 # Disable ICMP Redirect Acceptance net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.lo.accept_redirects = 0 net.ipv4.conf.eth0.accept_redirects = 0 net.ipv4.conf.default.accept_redirects = 0 # Enable Log Spoofed Packets, Source Routed Packets, Redirect Packets net.ipv4.conf.all.log_martians = 0 net.ipv4.conf.lo.log_martians = 0 net.ipv4.conf.eth0.log_martians = 0 # Disables IP source routing net.ipv4.conf.all.accept_source_route = 0 net.ipv4.conf.lo.accept_source_route = 0 net.ipv4.conf.eth0.accept_source_route = 0 net.ipv4.conf.default.accept_source_route = 0 # Enable IP spoofing protection, turn on source route verification net.ipv4.conf.all.rp_filter = 1 net.ipv4.conf.lo.rp_filter = 1 net.ipv4.conf.eth0.rp_filter = 1 net.ipv4.conf.default.rp_filter = 1 # Disable ICMP Redirect Acceptance net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.lo.accept_redirects = 0 net.ipv4.conf.eth0.accept_redirects = 0 net.ipv4.conf.default.accept_redirects = 0 # Disables the magic-sysrq key kernel.sysrq = 0 # Decrease the time default value for tcp_fin_timeout connection net.ipv4.tcp_fin_timeout = 15 # Decrease the time default value for tcp_keepalive_time connection net.ipv4.tcp_keepalive_time = 1800 # Turn off the tcp_window_scaling net.ipv4.tcp_window_scaling = 0 # Turn off the tcp_sack net.ipv4.tcp_sack = 0 # Turn off the tcp_timestamps net.ipv4.tcp_timestamps = 0 # Enable TCP SYN Cookie Protection net.ipv4.tcp_syncookies = 1 # Enable ignoring broadcasts request net.ipv4.icmp_echo_ignore_broadcasts = 1 # Enable bad error message Protection net.ipv4.icmp_ignore_bogus_error_responses = 1 # Log Spoofed Packets, Source Routed Packets, Redirect Packets net.ipv4.conf.all.log_martians = 1 # Increases the size of the socket queue (effectively, q0). net.ipv4.tcp_max_syn_backlog = 1024 # Increase the tcp-time-wait buckets pool size net.ipv4.tcp_max_tw_buckets = 1440000 # Allowed local port range net.ipv4.ip_local_port_range = 16384 65536
Agora, salve as alterações e saia do pico:
Para ativar:
/sbin/sysctl -p sysctl -w net.ipv4.route.flush=1
Leitura sugerida:
http://ipsysctl-tutorial.frozentux.net/ipsysctl-tutorial.html
Germano Pires Ferreira
Administrador Linux
![[Ask]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/ask.png)
![[blinklist]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/blinklist.png)
![[Bloglines]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/bloglines.png)
![[BlogMarks]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/blogmarks.png)
![[Blogsvine]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/blogsvine.png)
![[BUMPzee!]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/bumpzee.png)
![[CiteULike]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/citeulike.png)
![[co.mments]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/comments.png)
![[del.icio.us]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/delicious.png)
![[Digg]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/digg.png)
![[dzone]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/dzone.png)
![[Facebook]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/facebook.png)
![[Faves]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/faves.png)
![[Feed Me Links]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/feedmelinks.png)
![[Friendsite]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/friendsite.png)
![[Furl]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/furl.png)
![[Hugg]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/hugg.png)
![[Mixx]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/mixx.png)
![[MyWeb]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/myweb.png)
![[Technorati]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/technorati.png)
![[Yahoo!]](http://www.servidorgerenciado.com.br/wp-content/plugins/bookmarkify/yahoo.png)