The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security
Google UNIX.COM
Home Forums Register Rules & FAQ Members List Arcade Search Today's Posts Mark Forums Read


Security Anything involving computer security goes here.


Other UNIX.COM Threads You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Enable & disable cronjob Raynon Shell Programming and Scripting 7 09-19-2007 03:24 AM
SSH enable, Telnet disable ... ArabOracle.com SUN Solaris 14 03-02-2007 12:27 PM
Disable and Enable Backspace or Ctrl^H in vi mobile01 UNIX for Advanced & Expert Users 5 11-24-2006 07:55 AM
Enable/Disable rlogin and rcopy XP_2600 SUN Solaris 3 10-08-2006 06:52 PM
Enable and disable ttyS0 josramon Linux 1 12-01-2003 07:58 PM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-15-2008
Registered User
 

Join Date: Jul 2004
Posts: 6
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
How to disable RIP and enable EGP

Hello,

We recently had a Nessus scan done of our system and the solution to one of the findings was this:

disable the RIP agent and use an EGP routing protocol

I have been unable to find any specific instruction on how to do either. We are running Solaris 8.

Any help would be greatly appreciated. Thanks in advance.

stringman
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 02-15-2008
Registered User
 

Join Date: Feb 2008
Location: stockholm sweden
Posts: 12
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
Nowadays, when people talk about an EGP routing protocol, they aren't talking about the protocol called EGP. It went out of vogue a loong time ago. Insetad, they are talking of a class of protocols- External Gateway Protocol.

These are used to talk to other autonomous systems (think ISPs).

Today, there is only one modern EGP in existance, and thats BGPv4. But BGP is a 'meta-protocol' in such that it needs an IGP (internal gateway protocol) to actually send network topology data between your routers, assuming your net is more than one hop wide.

But judging from your post, this isnt the case. You have a unix machine which partakes in your networks' routing decisions, maybe because you have several interfaces? so you can have a dynamic routing table right?

RIP isn't insecure in itself. Perhaps you should just add some firewall rules which says that UDP to port 520 can only come from your friends' ip addresses? or your own net?

A rather long-winded reply, but hope I shed a little light on your question.
Reply With Quote
  #3 (permalink)  
Old 02-19-2008
Registered User
 

Join Date: Jul 2004
Posts: 6
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
Actually, we are not even connected to the internet. Our system is stand-alone. I know it's silly for Security to require this fix, but you can't fight the government. The concern is that someone will physically gain access to our system and therefore, come from our internal network. We don't even have a firewall, just a virus scan that must be run manually and Tripwire. But that's Ok w/ Security . However, they will not re-accredit our system unless we disable the RIP agent and use an EGP routing protocol (thier exact words).

stringman
Reply With Quote
  #4 (permalink)  
Old 02-19-2008
Neo's Avatar
Neo Neo is offline
Administrator
 

Join Date: Sep 2000
Location: Asia Pacific
Posts: 3,955
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
You can't trust scanning tools and their "analysis" to protect your system, you have to use your own brain, which is much smarter than unintelligent scanning tools.

You don't need a scanning tool to tell you how to configure your system, you need to answer basis questions, like "do I need any routing protocols at all?"

Also, your scanning tool is wrong and also obsolete.

RIP is an interior routing protocol. EGP is an obsolete exterior routing protocol call. If an automated scanning tool is telling you to disable RIP and enable EGP, you need to get a different scanning tool, period.
Reply With Quote
Google UNIX.COM
Reply



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:08 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger

Search Engine Optimization by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102