diff options
author | Eric Garver <e@erig.me> | 2016-05-26 12:28:05 -0400 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2016-05-30 01:40:53 -0400 |
commit | 176b346b37f0b9c03e91eb6f1460e00f3c0c3edf (patch) | |
tree | 39a55fd3ad282c635a9d19eb558e73b361f90894 /Documentation | |
parent | 68bb399e656f244d3d173a20a8280c167632fca8 (diff) |
Documentation: ip-sysctl.txt: clarify secure_redirects
Clarify how secure_redirects works. Mention that RFC1122 always applies.
Signed-off-by: Eric Garver <e@erig.me>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'Documentation')
-rw-r--r-- | Documentation/networking/ip-sysctl.txt | 8 |
1 files changed, 5 insertions, 3 deletions
diff --git a/Documentation/networking/ip-sysctl.txt b/Documentation/networking/ip-sysctl.txt index 6c7f365b1515..9ae929395b24 100644 --- a/Documentation/networking/ip-sysctl.txt +++ b/Documentation/networking/ip-sysctl.txt | |||
@@ -1036,15 +1036,17 @@ proxy_arp_pvlan - BOOLEAN | |||
1036 | 1036 | ||
1037 | shared_media - BOOLEAN | 1037 | shared_media - BOOLEAN |
1038 | Send(router) or accept(host) RFC1620 shared media redirects. | 1038 | Send(router) or accept(host) RFC1620 shared media redirects. |
1039 | Overrides ip_secure_redirects. | 1039 | Overrides secure_redirects. |
1040 | shared_media for the interface will be enabled if at least one of | 1040 | shared_media for the interface will be enabled if at least one of |
1041 | conf/{all,interface}/shared_media is set to TRUE, | 1041 | conf/{all,interface}/shared_media is set to TRUE, |
1042 | it will be disabled otherwise | 1042 | it will be disabled otherwise |
1043 | default TRUE | 1043 | default TRUE |
1044 | 1044 | ||
1045 | secure_redirects - BOOLEAN | 1045 | secure_redirects - BOOLEAN |
1046 | Accept ICMP redirect messages only for gateways, | 1046 | Accept ICMP redirect messages only to gateways listed in the |
1047 | listed in default gateway list. | 1047 | interface's current gateway list. Even if disabled, RFC1122 redirect |
1048 | rules still apply. | ||
1049 | Overridden by shared_media. | ||
1048 | secure_redirects for the interface will be enabled if at least one of | 1050 | secure_redirects for the interface will be enabled if at least one of |
1049 | conf/{all,interface}/secure_redirects is set to TRUE, | 1051 | conf/{all,interface}/secure_redirects is set to TRUE, |
1050 | it will be disabled otherwise | 1052 | it will be disabled otherwise |