Notes from Heck

Secure Arch Linux for a Public Server

net.ipv4.conf.default.rp_filter is set to 1 by default on Arch Linux systems. Check if it is so on your system by running:

sysctl net.ipv4.conf.default.rp_filter  

If it is 0, then add net.ipv4.conf.default.rp_filter=1 to 90-firewall.conf

Restart/Reload your firewall service after these changes:

# systemctl [reload|restart] iptables

Load the new kernel parameters:

# sysctl --system

Note for non-Arch users: If your distro relies on a single /etc/sysctl.conf file, then merge the contents of 90-firewall.conf into that file.

