<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ndd questions in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158936#M455950</link>
    <description>Guru's,&lt;BR /&gt;    I have 2 setrting that our IA group is freaking out about. They are:&lt;BR /&gt;ndd /dev/ip ip_forward_src_routed&lt;BR /&gt;1&lt;BR /&gt;and&lt;BR /&gt;# ndd /dev/ip ip_respond_to_echo_broadcast&lt;BR /&gt;1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;First, can I set these to 0? and secondly if I do, will this have any adverse effects?</description>
    <pubDate>Mon, 23 Feb 2009 19:26:01 GMT</pubDate>
    <dc:creator>Adam W.</dc:creator>
    <dc:date>2009-02-23T19:26:01Z</dc:date>
    <item>
      <title>ndd questions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158936#M455950</link>
      <description>Guru's,&lt;BR /&gt;    I have 2 setrting that our IA group is freaking out about. They are:&lt;BR /&gt;ndd /dev/ip ip_forward_src_routed&lt;BR /&gt;1&lt;BR /&gt;and&lt;BR /&gt;# ndd /dev/ip ip_respond_to_echo_broadcast&lt;BR /&gt;1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;First, can I set these to 0? and secondly if I do, will this have any adverse effects?</description>
      <pubDate>Mon, 23 Feb 2009 19:26:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158936#M455950</guid>
      <dc:creator>Adam W.</dc:creator>
      <dc:date>2009-02-23T19:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: ndd questions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158937#M455951</link>
      <description>&lt;A href="http://docs.hp.com/en/B9901-90044/ch10s02.html#echo_broadcast" target="_blank"&gt;http://docs.hp.com/en/B9901-90044/ch10s02.html#echo_broadcast&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;ICMP Echo Request Broadcasts (ip_respond_to_echo_broadcast)&lt;BR /&gt;&lt;BR /&gt;A ping message (ICMP echo request) to a broadcast address solicits responses from multiple systems and can generate a lot of network traffic. In security-conscious environments, HP recommends that you disable responses to broadcast echo requests.&lt;BR /&gt;0 (disable)&lt;BR /&gt;1 (enable)</description>
      <pubDate>Mon, 23 Feb 2009 19:41:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158937#M455951</guid>
      <dc:creator>Avinash20</dc:creator>
      <dc:date>2009-02-23T19:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: ndd questions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158938#M455952</link>
      <description>&lt;A href="http://www.cymru.com/Documents/ip-stack-tuning.html" target="_blank"&gt;http://www.cymru.com/Documents/ip-stack-tuning.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;With source routing, an attacker can attempt to reach internal IP addresses - including RFC1918 addresses. It is important to disable the acceptance of source routed packets to prevent subtle probes of your internal networks. &lt;BR /&gt;&lt;BR /&gt;HP-UX&lt;BR /&gt;    ndd -set /dev/ip ip_forward_src_routed 0 &lt;BR /&gt;    Disable this feature to prevent the host from forwarding source routed packets.</description>
      <pubDate>Mon, 23 Feb 2009 19:43:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158938#M455952</guid>
      <dc:creator>Avinash20</dc:creator>
      <dc:date>2009-02-23T19:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: ndd questions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158939#M455953</link>
      <description>Thank you much!</description>
      <pubDate>Mon, 23 Feb 2009 19:47:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158939#M455953</guid>
      <dc:creator>Adam W.</dc:creator>
      <dc:date>2009-02-23T19:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: ndd questions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158940#M455954</link>
      <description>Disabling ip_respond_to_echo_broadcast only means it won't respond to broadcast pings.  While some might think that makes a system more "secure," if it is talking on the net at all, it really doesn't make much of a difference.&lt;BR /&gt;&lt;BR /&gt;I always thought that ip_forward_src_routed was only important if ip_forwarding was enabled, but I cannot confirm that simply with ndd -h output on 11.11 :(  Still, if it makes your IA folks happy, it shouldn't really hurt anything.</description>
      <pubDate>Tue, 24 Feb 2009 01:35:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ndd-questions/m-p/5158940#M455954</guid>
      <dc:creator>rick jones</dc:creator>
      <dc:date>2009-02-24T01:35:34Z</dc:date>
    </item>
  </channel>
</rss>

