Great Circle Associates Firewalls
(March 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP_FORWARDING
From: jpf @ mig . com (Jack Flory)
Date: Fri, 4 Mar 1994 17:32:00 -0700 (MST)
To: verber @ parc . xerox . com (Mark Verber)
Cc: firewalls @ greatcircle . com
In-reply-to: <94Mar4 . 094424pst . 2440 @ avalon . parc . xerox . com> from "Mark Verber" at Mar 4, 94 09:44:15 am

>
> 
>> Wanted to test the results of turning on/off IP_FORWARDING in a Sun
>> 4.1.3.U1 kernel.  First of all, I haven't yet found the blurb about
>> where you make this change.  Have been browsing around in /sys/net and
>> looked through route.h, but couldn't find a mention of ipforwarding.
>> If anyone knows this off the top of their head, it would save me digging
>> through much piled paper.
>
>The file that ip_forwarding is declared in is /sys/netinet/ip_proto.c.
>Note: unless 4.1.3.U1 has changed from 4.1.3, turning off ip forwarding
>*does not* turn off source routing.  If you have full sources you need
>to modify /sys/netinet/ip_input.c or get a patch from Sun to disable
>source routes.  The default Sun configuration makes it trival for someone
>who has a modern telnet (like BSD 4.4 or NeXT's) to telnet through you
>firewall and into your internal network.
>

Excuse me, please correct me if I am wrong.  However, since this is
a BSD derived system, I thimk you might prefer to set 

options	IPFORWARDING

in your kernel config file rather than mucking about in
/sys/netinet/ip_proto.c.  This sets a manafest constant which
should do much more.


References:
Indexed By Date Previous: Re: IP_FORWARDING
From: randy @ psg . com (Randy Bush)
Next: Re: IP_FORWARDING
From: Mark Verber <verber @ parc . xerox . com>
Indexed By Thread Previous: Re: IP_FORWARDING
From: Mark Verber <verber @ parc . xerox . com>
Next: Re: IP_FORWARDING
From: Icarus Sparry <I . Sparry @ midge . bath . ac . uk>

Google
 
Search Internet Search www.greatcircle.com