| Securing and Optimizing Linux: RedHat Edition -A Hands on Guide | ||
|---|---|---|
| Prev | Chapter 5. General System Security | Next |
With the new version of Red Hat Linux 6.2 all kernel parameters available under the /proc/sys subdirectory of Linux can be configured at runtime. You can now use the new /etc/sysctl.conf file under Red Hat Linux 6.2 to modify and set kernel parameters at runtime. The sysctl.conf file is read and loaded each time the system reboots. All settings are now stored in the /etc/sysctl.conf file. All modifications to /proc/sys should be made through /etc/sysctl.conf, because they offer better for control, and are executed before rc.local or any other users scripts. We have shown you the networking security options that you must configure on your server for both Red Hat Linux version 6.1 and 6.2 below.

[root@deep] /#echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
|
[root@deep] /#echo 0 > /proc/sys/net/ipv4/icmp_echo_ignore_all
|

# Enable ignoring ping request
net.ipv4.icmp_echo_ignore_all = 1
|
[root@deep] /# /etc/rc.d/init.d/network restart
|
Setting network parameters [ OK ] Bringing up interface lo [ OK ] Bringing up interface eth0 [ OK ] Bringing up interface eth1 [ OK ]