diff --git a/rootdir/init.rc b/rootdir/init.rc index 9f444c19a..c0efeb176 100644 --- a/rootdir/init.rc +++ b/rootdir/init.rc @@ -114,6 +114,10 @@ on init # set fwmark on accepted sockets write /proc/sys/net/ipv4/tcp_fwmark_accept 1 + # disable icmp redirects + write /proc/sys/net/ipv4/conf/all/accept_redirects 0 + write /proc/sys/net/ipv6/conf/all/accept_redirects 0 + # Create cgroup mount points for process groups mkdir /dev/cpuctl mount cgroup none /dev/cpuctl cpu