Skip to content

Commit

Permalink
ipv4: Fix rp_filter description in net/ipv4/Kconfig.
Browse files Browse the repository at this point in the history
The reverse path filter (rp_filter) will NOT get enabled
when enabling forwarding.  Read the code and tested in
in practice.

Most distributions do enable it in startup scripts.

Signed-off-by: Jesper Dangaard Brouer <hawk@comx.dk>
Signed-off-by: David S. Miller <davem@davemloft.net>
  • Loading branch information
Jesper Dangaard Brouer authored and David S. Miller committed Feb 23, 2009
1 parent 0117cfa commit b2cc46a
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions net/ipv4/Kconfig
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ config IP_ADVANCED_ROUTER

at boot time after the /proc file system has been mounted.

If you turn on IP forwarding, you will also get the rp_filter, which
If you turn on IP forwarding, you should consider the rp_filter, which
automatically rejects incoming packets if the routing table entry
for their source address doesn't match the network interface they're
arriving on. This has security advantages because it prevents the
Expand All @@ -46,9 +46,11 @@ config IP_ADVANCED_ROUTER
rp_filter on use:

echo 1 > /proc/sys/net/ipv4/conf/<device>/rp_filter
or
and
echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter

Note that some distributions enable it in startup scripts.

If unsure, say N here.

choice
Expand Down

0 comments on commit b2cc46a

Please sign in to comment.