xtables target extension to strip all IP options from IPv4 packets
- iptables-dev
- Kernel headers
cd libxt_IPOPTSTRIP
make install
cd ../xt_IPOPTSTRIP
make
modprobe x_tables
insmod xt_IPOPTSTRIP.ko
Re-insert IP options for inbound packets
Engelhardt, Jan, and Nicolas Bouliane. "Writing Netfilter Modules." Revised, July 3 (2012).