- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Correct ip_pmtu_strategy
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 02:43 AM
04-12-2007 02:43 AM
I am finding conflicting recommendations for the ip_pmtu_strategy. I even find conflcting values for the default value of ip_pmtu_strategy. Our ip_pmtu_stategy is set to "1" which I always understood was the default. Now HP security bulletin says that "2" is the default.
We run HP-UX 11.23. We have patch PHNE_35182 which superceds PHNE_32606. We Quality Pack for March, 2007 loaded.
I know what each of the values does and I know that patches have been created to prevent DOS with certain value settings.
I just need to know what the setting should, if that is possible.
thanks,
Darrell Tschakert
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 02:50 AM
04-12-2007 02:50 AM
Re: Correct ip_pmtu_strategy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 02:57 AM
04-12-2007 02:57 AM
Re: Correct ip_pmtu_strategy
No, sorry, but this does not help. It is part of the problem. It contains the conflicting info that I mentioned in my posting. More current HP Security Bulletins such as HPSBUX01137 SSRT5954 rev.9 give different recommendations.
Thanks,
Darrell Tschakert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 03:07 AM
04-12-2007 03:07 AM
Re: Correct ip_pmtu_strategy
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 03:17 AM
04-12-2007 03:17 AM
Re: Correct ip_pmtu_strategy
-------------------------------------
Previous revisions of this Security Bulletin recommended setting
ip_pmtu_strategy to 0 or 3 as a workaround. Patches or updates
to resolve the issue are now available. After these patches or updates
are installed the workaround will no longer be necessary or recommended.
The ip_pmtu_strategy parameter should be restored to the default value of 2.
--------------------------------------
The document conflict in their recommendations. That later document claims that default is 2. The earlier says 1. Our is set to 1 and has never been changed to avoid the DOS problem.
Certainly someone out there must have a 11.23 system and has thought this one out after reading the HPSBUX01137 SSRT5954 rev.9. If so, what was your conclusion.
thanks,
Darrell Tschakert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 05:13 AM
04-12-2007 05:13 AM
SolutionI suspect the "Default being 2" message in the bulletin was a typo.
:/root# ndd -h ip_pmtu_strategy
ip_pmtu_strategy:
Set the Path MTU Discovery strategy:
0 Disables Path MTU Discovery. For any destination not directly
connected to the host, a maximum MTU of 576 is used;
1 Enables Path MTU Discovery;
2 Obsoleted, must not be used;
3 Disables Path MTU Discovery. For any destination not directly
connected to the host, the maximum MTU of the link is used.
When Path MTU Discovery is enabled all outbound datagrams have
the "Don't Fragment" bit set. This should result in notification
from any intervening gateway that needs to forward a datagram
down a path that would require additional fragmentation. When the
ICMP "Fragmentation Needed" message is received, IP updates its
MTU for the remote host. If the responding gateway implements the
recommendations for gateways in RFC1191, then the next hop MTU
will be included in the "Fragmentation Needed" message, and IP
will use it. If the gateway does not provide next hop
information, then IP will reduce the MTU to the next lower value
taken from a table of "popular" media MTUs.
[0,3] Default: 1
If you want to be sure, you can email bulletin_corrections@hp.com and security_alert@hp.com and ask those guys, who are the ones that write those.
Hope it helps
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 05:37 AM
04-12-2007 05:37 AM
Re: Correct ip_pmtu_strategy
I sent my well crafted questions off to the addresses that you gave me. They both bounced. The first time, I cut and pasted the addresses and the second time I entered them by hand. Are you sure about these addresses???
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 09:50 AM
04-12-2007 09:50 AM
Re: Correct ip_pmtu_strategy
Sorry about that, I don't know what's wrong with me today. Those should be dashes, not underscores.
security-alert@hp.com
bulletin-corrections@hp.com
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 11:38 PM
04-12-2007 11:38 PM
Re: Correct ip_pmtu_strategy
The first address appears to be valid. The second bounced as indicated below:
>> The following message to
However, I sent a second test email to the above address and, this time, it did not bounce. So, ??????.
Darrell T.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2007 11:47 PM
04-12-2007 11:47 PM
Re: Correct ip_pmtu_strategy
Correction: the bulletin-corrections@hp.com address bounced both times it was tried.
DT
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-17-2007 05:14 AM
04-17-2007 05:14 AM
Re: Correct ip_pmtu_strategy
I am going to leave ip_pmtu_strategy at "1" for now.
thanks,
Darrell Tschakert