RE: TCP/IP Stack Hardening

From: Mike Shaw (mike_at_shawnuff.net)
Date: 12/22/03

  • Next message: Scott Cleven-Mulcahy: "RE: TCP/IP Stack Hardening"
    Date: Mon, 22 Dec 2003 09:09:01 -0800
    To: AHoffmann@cta.net, frank@knobbe.us
    
    

    >2) Disable ICMP Redirect: In larger networks (well... at least network
    >with two different gateways) this is a shot in the foot. Most of
    >the
    >time you direct traffic to your default gateway (e.g. WAN router),
    > but
    >may need to redirect traffic to a different gateway (e.g. Internet
    >firewall). This one is noticed pretty quick though. It should be
    >set in
    >environments where only one gateway is present (for example, disable
    >ICMP Redirects on systems in the DMZ, but leave it enabled your
    >internal
    >systems).

    Heh...I've seen ICMP redirects used in effect as a routing protocol.
     Particularly in older mainframes where the IP code was fundamentally
    broken. Proxy ARP is another thing that often glosses over misconfigured
    networks.

    Before doing any of these hardening things, it's wise to do a thorough
    audit of all the adjacent network devices, and run a sniffer looking
    for layer 2 and ICMP chatter. I've rarely seen a network that didn't
    have something interesting pop up.

    -Mike
    CCNA, CISSP, YADDA, YADDA

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Scott Cleven-Mulcahy: "RE: TCP/IP Stack Hardening"

    Relevant Pages

    • Re: [SLE] connection redundancy
      ... which is the router just this side of the ... >>because it's own gateway is still up. ... You'll also need three network cards to put into this Linux box. ... your internal LAN can route packets to the Internet. ...
      (SuSE)
    • Re: Cant access secure Web pages
      ... and which need to be contacted via the Default Gateway. ... The Default Gateway being the software process that does the network ... Gateway (as set up by your ISP's DHCP packet to the router), ... me so I can send it directly (to the MAC address discovered by ARP). ...
      (uk.comp.sys.mac)
    • Re: Problem with Cable Moden & Router.
      ... gateway is the way in or out. ... a gateway leads to another network. ... Where two routes with different network masks overlap ...
      (comp.os.linux.misc)
    • RE: [SLE] Two network cards (dual-homed), two gateways? Desparatefor help
      ... > and server, and different for the clients on each of the two networks. ... network set the default gateway to the IP address of the network ... network, but SSH doesn't work. ...
      (SuSE)
    • Re: Dual NICs, Routing Problem
      ... There can only be one default gateway (unless you are using extra stuff as ... network that is NOT directly attached to one of your interfaces. ... >> Do all the hosts on 192.1.36.0 know that if they want to talk to any host on ... Here, the web server needs to know the IP of eth0 on the DataBase Server, ...
      (alt.os.linux.suse)