# ICMP Redirect Disabling

**URL:** <https://forums.suse.com/t/icmp-redirect-disabling/27534>\
**Category:** SLES Networking\
**Created:** [October 18, 2015, 9:54pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534 "2015-10-18T21:54:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![acastaneda32](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@acastaneda32](https://forums.suse.com/u/acastaneda32)\
**Post date:** [October 18, 2015, 9:54pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/1 "2015-10-18T21:54:56Z")

</div>

I am trying to set the following to 0 and running SLES 11 SP3

- net.ipv4.conf.all.secure\_redirects
- net.ipv4.conf.default.secure\_redirects

I’ve added the following to /etc/sysctl.conf and have rebooted the system:

# Disable response to broadcasts.

# You don’t want yourself becoming a Smurf amplifier.

net.ipv4.icmp\_echo\_ignore\_broadcasts = 1

# enable route verification on all interfaces

net.ipv4.conf.all.rp\_filter = 1

# enable ipV6 forwarding

#net.ipv6.conf.all.forwarding = 1

# increase the number of possible inotify(7) watches

fs.inotify.max\_user\_watches = 65536

# avoid deleting secondary IPs on deleting the primary IP

net.ipv4.conf.default.promote\_secondaries = 1  
net.ipv4.conf.all.promote\_secondaries = 1

# disable ICMP redirects

net.ipv4.send\_redirects = 0  
net.ipv4.conf.all.accept\_redirects = 0  
net.ipv4.conf.default.accept\_redirects = 0  
net.ipv4.conf.all.secure\_redirects = 0  
net.ipv4.conf.default.secure\_redirects = 0  
net.ipv4.tcp\_timestamps = 0

But when I run /sbin/sysctl -a, I still see the following:

net.ipv4.conf.default.secure\_redirects = 1  
net.ipv4.conf.all.secure\_redirects = 1

I then run /sbin/sysctl -p, and get the following output:

net.ipv4.icmp\_echo\_ignore\_broadcasts = 1  
net.ipv4.conf.all.rp\_filter = 1  
fs.inotify.max\_user\_watches = 65536  
net.ipv4.conf.default.promote\_secondaries = 1  
net.ipv4.conf.all.promote\_secondaries = 1  
/proc/sys/net/ipv4/send\_redirects: No such file or directory  
net.ipv4.conf.all.accept\_redirects = 0  
net.ipv4.conf.default.accept\_redirects = 0  
net.ipv4.conf.all.secure\_redirects = 0  
net.ipv4.conf.default.secure\_redirects = 0  
net.ipv4.tcp\_timestamps = 0

I then run /sbin/sysctl -a and see the following:

net.ipv4.conf.default.secure\_redirects = 0  
net.ipv4.conf.all.secure\_redirects = 0

However, after I reboot and run /sbin/sysctl -a, I still see the following:

net.ipv4.conf.default.secure\_redirects = 1  
net.ipv4.conf.all.secure\_redirects = 1

How can I get those two attributes to permanently be set to 0?

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [October 18, 2015, 10:19pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/2 "2015-10-18T22:19:56Z")

</div>

acastaneda32 Wrote in message:  
[color=blue]

> I am trying to set the following to 0 and running SLES 11 SP3
> 
> - net.ipv4.conf.all.secure\_redirects
> - net.ipv4.conf.default.secure\_redirects
> 
> I’ve added the following to /etc/sysctl.conf and have rebooted the  
> system:
> 
> # Disable response to broadcasts.
> 
> # You don’t want yourself becoming a Smurf amplifier.
> 
> net.ipv4.icmp\_echo\_ignore\_broadcasts = 1
> 
> # enable route verification on all interfaces
> 
> net.ipv4.conf.all.rp\_filter = 1
> 
> # enable ipV6 forwarding
> 
> #net.ipv6.conf.all.forwarding = 1
> 
> # increase the number of possible inotify(7) watches
> 
> fs.inotify.max\_user\_watches = 65536
> 
> # avoid deleting secondary IPs on deleting the primary IP
> 
> net.ipv4.conf.default.promote\_secondaries = 1  
> net.ipv4.conf.all.promote\_secondaries = 1
> 
> # disable ICMP redirects
> 
> net.ipv4.send\_redirects = 0  
> net.ipv4.conf.all.accept\_redirects = 0  
> net.ipv4.conf.default.accept\_redirects = 0  
> net.ipv4.conf.all.secure\_redirects = 0  
> net.ipv4.conf.default.secure\_redirects = 0  
> net.ipv4.tcp\_timestamps = 0
> 
> But when I run /sbin/sysctl -a, I still see the following:
> 
> net.ipv4.conf.default.secure\_redirects = 1  
> net.ipv4.conf.all.secure\_redirects = 1
> 
> I then run /sbin/sysctl -p, and get the following output:
> 
> net.ipv4.icmp\_echo\_ignore\_broadcasts = 1  
> net.ipv4.conf.all.rp\_filter = 1  
> fs.inotify.max\_user\_watches = 65536  
> net.ipv4.conf.default.promote\_secondaries = 1  
> net.ipv4.conf.all.promote\_secondaries = 1  
> /proc/sys/net/ipv4/send\_redirects: No such file or directory  
> net.ipv4.conf.all.accept\_redirects = 0  
> net.ipv4.conf.default.accept\_redirects = 0  
> net.ipv4.conf.all.secure\_redirects = 0  
> net.ipv4.conf.default.secure\_redirects = 0  
> net.ipv4.tcp\_timestamps = 0
> 
> I then run /sbin/sysctl -a and see the following:
> 
> net.ipv4.conf.default.secure\_redirects = 0  
> net.ipv4.conf.all.secure\_redirects = 0
> 
> However, after I reboot and run /sbin/sysctl -a, I still see the  
> following:
> 
> net.ipv4.conf.default.secure\_redirects = 1  
> net.ipv4.conf.all.secure\_redirects = 1
> 
> How can I get those two attributes to permanently be set to 0?[/color]

I suspect your two settings are being reset by a module loading  
after the sysctl stuff is initially processed. Your best bet is  
probably to put the appropriate two sysctl commands in  
/etc/init.d/after.local file so they’re processed at the end of  
the system startup.

## HTH.

Simon Flood  
SUSE Knowledge Partner

----Android NewsGroup Reader----  
[http://usenet.sinaapp.com/](http://usenet.sinaapp.com/)

---

<div class="post-metadata">

**Author:** ![acastaneda32](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@acastaneda32](https://forums.suse.com/u/acastaneda32)\
**Post date:** [October 18, 2015, 11:04pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/3 "2015-10-18T23:04:25Z")

</div>

I don’t see an after.local file there. Is that something I’d need to create? If so, how should I create the file? Thanks for the help.

/etc/init.d\> ls -a  
. boot.apparmor boot.dmraid boot.lvm boot.udev\_retry haldaemon kexec ntp raw reboot slpd xdm  
… boot.cgroup boot.efivars boot.lvm\_monitor cron halt lvm\_wait\_merge\_snapshot openct rc rpasswdd smartd xfs  
aaeventd boot.cleanup boot.fuse boot.md cups halt.local mcelog openwsmand rc0.d rpcbind smb xinetd  
acpid boot.clock boot.ipconfig boot.multipath dbus haveged mdadmd pcscd rc1.d rpmconfigcheck smbfs ypbind  
alsasound boot.compliance boot.kdump boot.proc .depend.boot inputattach microcode.ctl pm-profiler rc2.d rsyncd splash  
arpd boot.crypto boot.klog boot.quota .depend.halt ipmi multipathd postfix rc3.d saslauthd splash\_early  
atd boot.crypto-early boot.ldconfig boot.rootfsck .depend.start ipmievd network powerd rc4.d setserial sshd  
auditd boot.cycle boot.loadmodules boot.scpm .depend.stop irq\_balancer network-remotefs powerfail rc5.d sfcb SuSEfirewall2\_init  
autofs boot.d boot.local boot.swap earlysyslog ivman nfs puppet rc6.d single SuSEfirewall2\_setup  
autoyast boot.debugfs boot.localfs boot.sysctl fbset joystick nmb purge-kernels rcS.d skeleton syslog  
boot boot.device-mapper boot.localnet boot.udev gpm kbd nscd random README skeleton.compat uuidd

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [October 19, 2015, 4:45am UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/4 "2015-10-19T04:45:25Z")

</div>

Duplicating my response from the openSUSE version of your thread  
[http://forums.opensuse.org/showthread.php?t=510303:](http://forums.opensuse.org/showthread.php?t=510303:)

Every time I’ve fought with sysctl stuff in this way the problem has been  
caused by either changing networks or doing something else that refreshes  
the firewall. The SuSEfirewall2 service appears to do some sysctl hacking  
automatically and I’ve never figured out how to trump it other than by  
adding a custom firewall script to the end of the SuSEfirewall2 version  
which runs the sysctl commands manually after any firewall change. This  
is not pretty, but it works reliably,at least on SUSE Linux Enterprise  
Server (SLES) 11.

Look at the /etc/sysconfig/SuSEfirewall2 file, for the name of the custom  
script (/etc/sysconfig/scripts/SuSEfirewall2-custom); uncomment the line,  
and then modify that file (it should already exist waiting for input)  
adding your sysctl command to the correct section. The correct section  
could probably be ‘fw\_custom\_after\_finished’ if nothing else works.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [October 19, 2015, 12:40pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/5 "2015-10-19T12:40:29Z")

</div>

On 18/10/2015 21:14, acastaneda32 wrote:  
[color=blue]

> I don’t see an after.local file there. Is that something I’d need to  
> create? If so, how should I create the file? Thanks for the help.[/color]

No the /etc/init.d/after.local doesn’t exist by default on SLES so  
you’ll need to create and edit it using your favourite editor. It’s just  
a simple shell script.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.

---

<div class="post-metadata">

**Author:** ![acastaneda32](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@acastaneda32](https://forums.suse.com/u/acastaneda32)\
**Post date:** [October 19, 2015, 7:25pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/6 "2015-10-19T19:25:58Z")

</div>

Thanks smflood! I ended up creating the after.local file and adding the following:

sudo /sbin/sysctl -p

I rebooted the system and both the following are set to 0.

net.ipv4.conf.default.secure\_redirects = 0  
net.ipv4.conf.all.secure\_redirects = 0

In the future, I’ll just need to modify the sysctl.conf file for any additional changes.

---

<div class="post-metadata">

**Author:** ![acastaneda32](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@acastaneda32](https://forums.suse.com/u/acastaneda32)\
**Post date:** [October 19, 2015, 7:28pm UTC](https://forums.suse.com/t/icmp-redirect-disabling/27534/7 "2015-10-19T19:28:19Z")

</div>

Thanks. I’m going to try this in test environment, but successfully using the after.local file currently.
