Code: Select all
hw.kbd.keymap_restrict_change=4
kern.sugid_coredump=0
net.inet.icmp.bmcastecho=0
net.inet.icmp.drop_redirect=1
net.inet.ip.accept_sourceroute=0
net.inet.ip.check_interface=1
net.inet.ip.forwarding=0
net.inet.ip.process_options=0
net.inet.ip.random_id=1
net.inet.ip.redirect=0
net.inet.ip.sourceroute=0
net.inet.tcp.always_keepalive=0
net.inet.tcp.blackhole=2
net.inet.tcp.drop_synfin=1
net.inet.tcp.icmp_may_rst=0
net.inet.tcp.nolocaltimewait=1
net.inet.tcp.path_mtu_discovery=0
net.inet.udp.blackhole=1
net.inet6.icmp6.rediraccept=0
net.inet6.ip6.forwarding=0
net.inet6.ip6.fw.enable=1
net.inet6.ip6.redirect=0
But fact is I don't know what each of those lines actually do. So whoever wrote that wiki page must add the purpose of all of those lines.
One more thing. Its written that the following lines will change the user experience.
Code: Select all
security.bsd.hardlink_check_gid=1
security.bsd.hardlink_check_uid=1
security.bsd.see_other_gids=0
security.bsd.see_other_uids=0
security.bsd.stack_guard_page=1
security.bsd.unprivileged_proc_debug=0
security.bsd.unprivileged_read_msgbuf=0