Hardening sysctl

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
dwrtss
DD-WRT Novice


Joined: 13 Dec 2023
Posts: 1

PostPosted: Wed Dec 13, 2023 11:59    Post subject: Hardening sysctl Reply with quote
I want to harden my dd-wrt router a bit more. Which of the sysctls in this guide I can configure on my router too? `https://madaidans-insecurities.github.io/guides/linux-hardening.html#sysctl`

Is there any topic for hardening dd-wrt?

Like the value of `dev.tty.ldisc_autoload` in dd-wrt is set as 1. But can I set it to 0 without any issues?

What about
```
net.ipv4.tcp_sack=0
net.ipv4.tcp_dsack=0
net.ipv4.tcp_fack=0
```

dd-wrt have some of the values set on 1. Its better to change it to 0?

Which other sysctls values I can harden without issues?
Sponsor
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Wed Dec 13, 2023 15:00    Post subject: Reply with quote
Hi and welcome to the forum...always make sure when you have a question to post your,
router model and current firmware number...as this matters a lot..!

DDWRT is not like the normal linux distros, if you want to explore setting, syscrtl values or nvram settings, you can always reset, if something is not well..but, remember some values are critical for the system operation, as this Linux is very much network oriented...so, all other functions are castrated...and not present...and there is only one user...

Even on my pc Linux, if i fiddle too much with hardening settings, In order to harden it, I more like to break something...same with Firefox browser or any other hardening settings anywhere...so you are on your own... Cool

https://github.com/torvalds/linux/blob/master/Documentation/driver-api/tty/tty_ldisc.rst

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum