please turn on rp_filter by default

Bug #201952 reported by James Troup
2
Affects Status Importance Assigned to Milestone
procps (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: procps

Hi,

Please consider turning on rp_filter by default. I appreciate it
doesn't work for people with certain setups (e.g. multi-homed
gateway/routers), but I'd argue that those people are very much in the
minority and that they're kind of people who would/could know they
need to turn off rp_filter. Having it on for the majority of people
who will only gain from it would seem like the right choice.

--
James

Related branches

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package procps - 1:3.2.7-5ubuntu2

---------------
procps (1:3.2.7-5ubuntu2) hardy; urgency=low

  * debian/sysctl.conf:
    - enable "rp_filter" by default (LP: #201952).
    - clean up duplicated entries, adjust documentation about syn cookies.

 -- Kees Cook <email address hidden> Thu, 13 Mar 2008 14:13:26 -0700

Changed in procps:
status: New → Fix Released
Revision history for this message
Mark Deneen (mdeneen) wrote :

Please consider reversing this, or at least disabling it in the ike package. Having it enabled breaks the shrew ike vpn client, and it is not at all obvious as to why.

There is already a bug open for this: https://bugs.launchpad.net/ubuntu/+source/ike/+bug/465736

Revision history for this message
Mark Deneen (mdeneen) wrote :

Adding the bug link like this #465736 for referencing.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.