<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bastille does not lock down ip_forwarding in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-does-not-lock-down-ip-forwarding/m-p/5155911#M732327</link>
    <description>/var/opt/sec_mgmt/bastille/TODO.txt :)&lt;BR /&gt;&lt;BR /&gt;Yes manual entry needed&lt;BR /&gt;</description>
    <pubDate>Tue, 10 Feb 2009 06:01:55 GMT</pubDate>
    <dc:creator>CITEC HP TEAM</dc:creator>
    <dc:date>2009-02-10T06:01:55Z</dc:date>
    <item>
      <title>Bastille does not lock down ip_forwarding</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-does-not-lock-down-ip-forwarding/m-p/5155910#M732326</link>
      <description>As per the doco running Bastille for HOST.config should lock down ip_forwaring and update /etc/rc.config.d/nndconf with the following:&lt;BR /&gt;&lt;BR /&gt;The following ndd changes will be made:&lt;BR /&gt;&lt;BR /&gt;ip_forward_directed_broadcasts=0&lt;BR /&gt;ip_forward_src_routed=0&lt;BR /&gt;ip_forwarding=0&lt;BR /&gt;ip_ire_gw_probe=0&lt;BR /&gt;ip_pmtu_strategy=1&lt;BR /&gt;ip_send_source_quench=0&lt;BR /&gt;tcp_conn_request_max=4096&lt;BR /&gt;tcp_syn_rcvd_max=1000&lt;BR /&gt;&lt;BR /&gt;We have run this on several 11.11 and 11.23 systems and nndconf was not updated.&lt;BR /&gt;&lt;BR /&gt;However, for 11.31 it was.&lt;BR /&gt;&lt;BR /&gt;Does anyone know the cause?&lt;BR /&gt;&lt;BR /&gt;If these settings are not already in the file then is it the case that running bastille with HOST.config will not update nndconf?&lt;BR /&gt;&lt;BR /&gt;Many thanks,&lt;BR /&gt;USG2 - CITEC</description>
      <pubDate>Tue, 10 Feb 2009 05:36:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bastille-does-not-lock-down-ip-forwarding/m-p/5155910#M732326</guid>
      <dc:creator>CITEC HP TEAM</dc:creator>
      <dc:date>2009-02-10T05:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Bastille does not lock down ip_forwarding</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-does-not-lock-down-ip-forwarding/m-p/5155911#M732327</link>
      <description>/var/opt/sec_mgmt/bastille/TODO.txt :)&lt;BR /&gt;&lt;BR /&gt;Yes manual entry needed&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Feb 2009 06:01:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bastille-does-not-lock-down-ip-forwarding/m-p/5155911#M732327</guid>
      <dc:creator>CITEC HP TEAM</dc:creator>
      <dc:date>2009-02-10T06:01:55Z</dc:date>
    </item>
  </channel>
</rss>

