HomeFreeBSD

Add net.inet6.ip6.source_address_validation

Description

Add net.inet6.ip6.source_address_validation

Drop packets arriving from the network that have our source IPv6
address. If maliciously crafted they can create evil effects
like an RST exchange between two of our listening TCP ports.
Such packets just can't be legitimate. Enable the tunable
by default. Long time due for a modern Internet host.

Reviewed by: melifaro, donner, kp
Differential revision: https://reviews.freebsd.org/D32915

Details

Provenance
glebiusAuthored on Nov 12 2021, 5:01 PM
Reviewer
melifaro
Differential Revision
D32915: Add net.inet6.ip6.source_address_validation
Parents
rG2ce85919bbba: Add net.inet.ip.source_address_validation
Branches
Unknown
Tags
Unknown