LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-01-2005, 08:26 PM   #1
rjcrews
Member
 
Registered: Apr 2004
Distribution: Debian
Posts: 193

Rep: Reputation: 30
msec and ICMP ping problem


Hi all -

I am using msec for security (mandrake) and no iptables.

I know how to change the various levels of msec , but i am having a problem setting my server to reply to pings.

The "level" i want to use for msec writes the following line to my sysctl.conf file:


Code:
net.ipv4.icmp_ignore_bogus_error_responses=1
net.ipv4.conf.all.rp_filter=1
net.ipv4.icmp_echo_ignore_broadcasts=1
net.ipv4.icmp_echo_ignore_all=1
net.ipv4.conf.all.log_martians=1
The sysctl has at the top which is not rewritten when i change anything:

Code:
# Controls IP packet forwarding
#net.ipv4.ip_forward = 0
# Disables IP dynaddr
net.ipv4.ip_dynaddr = 0
# Disable ECN
net.ipv4.tcp_ecn = 0
# Controls source route verification
net.ipv4.conf.default.rp_filter = 1
I changed in the /usr/share/msec/level.x file a line that had:


Code:
accept_icmp_echo no
to

Code:
accept_icmp_echo yes



So my question is, how/what do i need to change to have the server respong to pings.

Also , a seconday question, what is the difference between ignore_broadcasts and ignore_all?

*edit* I put this in here bc it involves msec, if it is more appropriate somewhere else please move it


Thanks in advance!
 
Old 12-05-2005, 11:37 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Did you also change icmp_echo_ignore_all=1 to 0?

Note that these will probably be reset by msec, so you may need to override that setting.

Also , a seconday question, what is the difference between ignore_broadcasts and ignore_all?
Ignore_broadcasts only blocks ping packets sent to the broadcast address of your particular network (so all hosts on your network would respond to the echo request). Pinging a particular host on the LAN would be fine. Ignore_all is just what it sounds like...ignore all. The ignore_broadcast setting is used to prevent certain types of DoS attacks like smurf. Your border firewall should never allow remote hosts to ping the local network broadcast otherwise you'll find your bandwidth being used as a smurf amplifier.
 
Old 12-06-2005, 05:06 AM   #3
rjcrews
Member
 
Registered: Apr 2004
Distribution: Debian
Posts: 193

Original Poster
Rep: Reputation: 30
Yes I changed net.ipv4.icmp_echo_ignore_all=1 to 0, in the sysctl file. MSEC overrode it.

Thx for the reply.
 
Old 12-06-2005, 06:45 AM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Use the draksec graphical utility to change the icmp echo setting (should be under network settings tab).
 
Old 12-06-2005, 06:59 AM   #5
rjcrews
Member
 
Registered: Apr 2004
Distribution: Debian
Posts: 193

Original Poster
Rep: Reputation: 30
I am trying this:

Code:
echo 0 > /proc/sys/net/ipv4/icmp_echo_ignore_all
Wonder if this will keep it on though, bc the sysctl will has otherwise.

I will see! Thanks Capt_Caveman
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Fedora Core 3, GRC port scan says ports arestealthed but responds to icmp ping IraB Linux - Security 7 12-09-2004 11:18 PM
ICMP traffic archives/writing ICMP traffic in a file maia_1 Programming 0 07-20-2004 03:43 AM
Can't ping - iptable problem (possibly ICMP or OUTPUT) hamish Linux - Networking 3 04-21-2004 08:30 PM
What is ICMP Ping Cyber kit 2.2 windows fotoguy Linux - Security 6 12-27-2003 06:30 PM
Problem with ICMP rights bimble Linux - General 5 11-20-2002 10:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration