Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp

From: Ruslan Ermilov (ru_at_freebsd.org)
Date: 09/24/03

  • Next message: Dag-Erling Smørgrav: "Re: OpenSSH: multiple vulnerabilities in the new PAM code"
    Date: Wed, 24 Sep 2003 20:46:32 +0300
    To: Bruce M Simpson <bms@spc.org>
    
    
    
    

    On Wed, Sep 24, 2003 at 06:39:00PM +0100, Bruce M Simpson wrote:
    > On Wed, Sep 24, 2003 at 07:21:11PM +0300, Ruslan Ermilov wrote:
    > > On Wed, Sep 24, 2003 at 07:44:26AM -0700, Michael Sierchio wrote:
    > > > Using static ARP entries and turning off ARP on the interface
    > > > should be a workaround. Whether this is remotely feasible
    > > > depends on your situation.
    > > >
    > > I still have not committed the code that supports static ARP
    > > on an interface -- there's currently no way to do static ARP
    > > only, if you disable ARP on an interface it will be disabled
    > > in its whole.
    >
    > I'd like to review and potentially test this patch before it goes in, as it
    > sounds interesting and useful to us.
    >
    Attached.

    Cheers,

    -- 
    Ruslan Ermilov		Sysadmin and DBA,
    ru@sunbay.com		Sunbay Software Ltd,
    ru@FreeBSD.org		FreeBSD committer
    
    

    
    




  • Next message: Dag-Erling Smørgrav: "Re: OpenSSH: multiple vulnerabilities in the new PAM code"

    Relevant Pages

    • Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp
      ... >>Using static ARP entries and turning off ARP on the interface ... > I still have not committed the code that supports static ARP ... if you disable ARP on an interface it will be disabled ... it's just *kidding* about the NOARP flag? ...
      (FreeBSD-Security)
    • Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp
      ... >> Using static ARP entries and turning off ARP on the interface ... >> should be a workaround. ... > I still have not committed the code that supports static ARP ... if you disable ARP on an interface it will be disabled ...
      (FreeBSD-Security)
    • Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp
      ... >>There is no known workaround at this time. ... I still have not committed the code that supports static ARP ... on an interface -- there's currently no way to do static ARP ... if you disable ARP on an interface it will be disabled ...
      (FreeBSD-Security)
    • Re: VIO Virtual Ethernet Security
      ... if I have to disable arp and build a static arp table.) ... It even works for inspection purposes. ... factors may re-establish direct communications. ...
      (comp.unix.aix)
    • Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp
      ... >>I still have not committed the code that supports static ARP ... if you disable ARP on an interface it will be disabled ... IFF_NOARP flag is set on an interface. ...
      (FreeBSD-Security)