How to enable "strict multihoming" on AIX?

From: Steve Greenland (steveg_at_molehole.dyndns.org)
Date: 10/31/03


Date: 31 Oct 2003 15:08:53 GMT

It seems that AIX (4.3.3, 5.1) allows connections to all the addresses
on a given host via any of the interfaces. For example, I can (ping,
connect to) address 192.168.0.7 on en1 from a different subnet connected
to en0 on, say, 192.168.15.1. (Assuming routing on the client is set
to appropriately, of course.) Sometimes this is how you want things to
work, but not necessarily.

On Solaris, you can prevent this by enabling 'strict_multihoming'.
Linux provides the rp_filter parameter to accomplish a similar (but not
identical) effect. Looking at the 'no' manpage and searching the web
have not produced a similar parameter for AIX; I've tried to several of
the 'no' settings that seemed like they might work (either directly or
by side effect), but no luck. Am I just missing it?

No, disabling IP forwarding does not stop this: it prevents going
*through* the multi-homed host, but not to arbitrary addresses *on* the
host.

BTW, I have figured how to accomplish it via the packet filter (genfilt
et. al.), but it seems like overkill for a fairly simple problem.

Thanks,
Steve

-- 
Steve Greenland
    The irony is that Bill Gates claims to be making a stable operating
    system and Linus Torvalds claims to be trying to take over the
    world.       -- seen on the net


Relevant Pages

  • Re: IBM FastT vs. EMC Clarion
    ... AIX hosts have to be shutdown when doing the firmware upgrade ... any AIX servers attached to that unit will have to be shutdown. ... interrupting host I/O access to the array. ... interrupting host I/O access to the array thousands of times with many ...
    (AIX-L)
  • Re: Strange netstat output - possible hacking attempt?
    ... >> think we can really call that 'port scanning' in any illegitimate sense. ... > out to the colo swerver, the ISP would cut the link, outgoing packets would ... "Requests per 10 seconds per host rule" and only inforcing these rules ... connections making it a WAN. ...
    (comp.os.linux.security)
  • Pocket PC (iPaq 4350) fails to make wireless connection even after replacing motherboard!
    ... Established connections reset: 2 ... Host Name: localhost ... INC Vendor: High Tech Computer ... Host Name: WINDOWSMOBILE97 ...
    (microsoft.public.pocketpc)
  • Re: Error messages for remote desktop connection attempt
    ... Did you enable Remote Desktop connections on the XP Pro host? ... have you checked the EventLog on the host? ... "The net logon service on the local computer started and then ...
    (microsoft.public.windows.terminal_services)
  • Re: kerberos AD: keytab and service principal not needed?
    ... I've set up our AIX 5.2 and 5. ... The setup procedure on the AIX side involves: ... Create Windows account with ktpass with a service principal in the ... which you then copy to the AIX host as /etc/krb5/krb5.keytab ...
    (comp.unix.aix)