Re: Deactivation of source routing

From: Alex Noordergraaf (alex.noordergraaf@sun.com)
Date: 11/21/01


Message-ID: <3BFAEC5F.928FBC0A@sun.com>
Date: Tue, 20 Nov 2001 18:50:55 -0500
From: Alex Noordergraaf <alex.noordergraaf@sun.com>
To: Yannick Lo Guidice <ylg@fr.ibm.com>
Subject: Re: Deactivation of source routing

Yannick Lo Guidice wrote:
>
> Hi all,
>
> I want to know how to check/activate/deactivate the IP source routing under
> Solaris 2.6. Can anyone helps ?

This is covered in detail in the BluePrint OnLine article 'Solaris OE
Network Settings for Security: updated for Solaris 8 OE' pages 15 and
16. The article is available at:

   http://www.sun.com/blueprints/1200/network-updt1.pdf

The short version of how to disable ip_forward_src_routed is to use the
following command:

   ndd -set /dev/ip ip_forward_src_routed 0

There is a script (nddconfig) available from
http://sun.com/security/blueprints which can be used to automate setting
this option and the others Keith and I recommend.

HTH, Alex

>
> Thanks
>
> --
> Yannick Lo Guidice
> email : ylg@fr.ibm.com
> tel : 04 9211 5967
> fax : 04 9211 5959
> Security & FW Support
> IBM Global Services NDSC France

--
Alex Noordergraaf                  (voice) 781.442.3447
Enterprise Eng. Security Architect (email) alex.noordergraaf@sun.com
BluePrints Security articles       http://sun.com/security/blueprints