Great Circle Associates Firewalls
(March 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP_FORWARDING
From: Mark Verber <verber @ parc . xerox . com>
Date: Fri, 4 Mar 1994 20:33:02 PST
To: kannan @ catarina . usc . edu, verber @ parc . xerox . com
Cc: firewalls @ greatcircle . com, jpf @ mig . com

> Given that we are talking about sunos machines, on sunos 4.*:
> Actually, you want to set IPFORWARDING=-1.  Setting it to 0 disables
> forwarding on a single homed machine, and re-enables it (sets it back
> to 1) on a multi-homed machine.  Setting it to -1 leaves it
> permanently disabled.
> 
> When disabled, source routing only happens if the packet leaves on the
> same interface it arrived at.
> 

Right, but if you have a firewall setup something like this:

Nasty World
	|
	|
	*-------+-------+-------
      router	|	|
		|    other hosts
	Bastion Host


where the router filtering packets to go to just the bastion host which
is a proxy server but not blocking source routes, -or-

Nasty World
	|
	|		   internal router
	*-------+---------------*
     ext router	|		|
		|		|
	Bastion Host	   Internal Net

where the external router isn't blocking source routes and the internal
router isn't properly configured you are vulnerable since the source routed
packet comes in and goes out on the same interface.

I realize that this involves two or three misconfigurations.... a
series of mistakes that most of us would not make, but it is best to
close off all possible problems, especially given cisco's history of
bugging handling of source route, eg the CERT advisory a while ago.

--mark

Indexed By Date Previous: Re: IP_FORWARDING
From: kannan @ catarina . usc . edu
Next: Firewalls temporarily moderated to stifle anonymous email flame war
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>
Indexed By Thread Previous: Re: IP_FORWARDING
From: kannan @ catarina . usc . edu
Next: Re: IP_FORWARDING
From: db @ whitney . sunbim . be (Danny Backx)

Google
 
Search Internet Search www.greatcircle.com