Custom Search

Thursday, July 17, 2008

Prevent ping/icmp attack using kernel parameter

Prevent ping/icmp attacks using kernel parameter

Write the following line in the file "/etc/sysctl.conf"
net.ipv4.icmp_echo_ignore_all = 1
Save the file & restart network service [command: service network restart]
OR
Save the file & run "sysctl -p"

We can also change the value of this runtime kernel parameter to 0 (zero) using the command:
echo "0" > /proc/sys/net/ipv4/icmp_echo_ignore_all

If the value is "1" -->> The system will ignore all icmp/ping requests.
If the value is "0" -->> The system will accept all icmp/ping requests.

1 comment:

Anonymous said...

How this can be done on IPv6 interface?

 
Watch the latest videos on YouTube.com