Hi,
"no ip redirects" disables "ICMP redirects" in the interface.
In the first glance, "ICMP redirects" is good as it always provide the optimum route. Check this link on how "ICMP redirects" work http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080094702.shtml
However, "ICMP redirects" present a potent DOS (Denial Of Service) attack. If the target
system does accept ICMP redirects (and packets can actually reach it) that system can be stopped from talking to any particular address on the net. Also, attacks can be launch from anywhere - not necessary from the local network.
Following are links to IOS Hardening which discusses "no ip redirects" and other feature
http://www.cymru.com/Documents/secure-ios-template.html
http://www.nsa.gov/snac/
Regards,
Dandy