Visit Our UNIX and Linux User Community


How to disable RIP and enable EGP


 
Thread Tools Search this Thread
Special Forums Cybersecurity How to disable RIP and enable EGP
# 1  
Old 02-15-2008
How to disable RIP and enable EGP

Hello,

We recently had a Nessus scan done of our system and the solution to one of the findings was this:

disable the RIP agent and use an EGP routing protocol

I have been unable to find any specific instruction on how to do either. We are running Solaris 8.

Any help would be greatly appreciated. Thanks in advance.

stringman
# 2  
Old 02-15-2008
Nowadays, when people talk about an EGP routing protocol, they aren't talking about the protocol called EGP. It went out of vogue a loong time ago. Insetad, they are talking of a class of protocols- External Gateway Protocol.

These are used to talk to other autonomous systems (think ISPs).

Today, there is only one modern EGP in existance, and thats BGPv4. But BGP is a 'meta-protocol' in such that it needs an IGP (internal gateway protocol) to actually send network topology data between your routers, assuming your net is more than one hop wide.

But judging from your post, this isnt the case. You have a unix machine which partakes in your networks' routing decisions, maybe because you have several interfaces? so you can have a dynamic routing table right?

RIP isn't insecure in itself. Perhaps you should just add some firewall rules which says that UDP to port 520 can only come from your friends' ip addresses? or your own net?

A rather long-winded reply, but hope I shed a little light on your question.
# 3  
Old 02-19-2008
Actually, we are not even connected to the internet. Our system is stand-alone. I know it's silly for Security to require this fix, but you can't fight the government. The concern is that someone will physically gain access to our system and therefore, come from our internal network. We don't even have a firewall, just a virus scan that must be run manually and Tripwire. But that's Ok w/ Security Smilie. However, they will not re-accredit our system unless we disable the RIP agent and use an EGP routing protocol (thier exact words).

stringman
# 4  
Old 02-19-2008
You can't trust scanning tools and their "analysis" to protect your system, you have to use your own brain, which is much smarter than unintelligent scanning tools.

You don't need a scanning tool to tell you how to configure your system, you need to answer basis questions, like "do I need any routing protocols at all?"

Also, your scanning tool is wrong and also obsolete.

RIP is an interior routing protocol. EGP is an obsolete exterior routing protocol call. If an automated scanning tool is telling you to disable RIP and enable EGP, you need to get a different scanning tool, period.

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Infrastructure Monitoring

OID to disable/enable printing

Hi @ all, we are a non-profit educational organisation. Now my company wants to disable printers, when a room is not used. I do a lot monitoring, using snmp. So I had the idea of disabling and enabling the printers by using snmp. After searching for hours, I only found some status-objects (ro)... (1 Reply)
Discussion started by: karls0
1 Replies

2. HP-UX

FTP service Enable/Disable

hi everybody, I can easily enable /disable the FTP service from SAM, how can I do this via command line? using inetd? how? cheers, messi (1 Reply)
Discussion started by: messi777
1 Replies

3. UNIX for Dummies Questions & Answers

Enable and disable the auto mount

How to enable and disable the auto mount option for USB devices.? (3 Replies)
Discussion started by: ungalnanban
3 Replies

4. UNIX for Dummies Questions & Answers

crontab: disable/enable

since i don't have root access, i have been doing: crontab -l > /tmp/username.crontab crontab -r vi /tmp/username.crontab and copy page crontab -e, and paste sometimes, /tmp/username.crontab has more than 1 page, so i have to copy twice. how do i copy all contents from... (2 Replies)
Discussion started by: tjmannonline
2 Replies

5. Shell Programming and Scripting

How to disable Enable/Disable Tab Key

Hi All, I have bash script, so what is sintax script in bash for Enable and Disable Tab Key. Thanks for your help.:( Thanks, Rico (1 Reply)
Discussion started by: carnegiex
1 Replies

6. UNIX for Dummies Questions & Answers

Disable RIP in SCO Uniix

Is it possible to switch off RIP protocol in SCO Unix - if so how's it done ?:confused: (1 Reply)
Discussion started by: dewi.edwards
1 Replies

7. Solaris

SSH enable, Telnet disable ...

Hi... How do I enable SSH and disable telnet.. Also - is there anything special I need to do to ensure that a new user can use ssh and su but not telnet? Adel (15 Replies)
Discussion started by: ArabOracle.com
15 Replies

8. Shell Programming and Scripting

Enable & disable cronjob

Hi All, I am new to cronjob and need some guidance on this. 1) How do i enable a cronjob ? Can it be done by "crontab mycronfile" or "crontab -e mycronfile" 2) How can i disable the cronjob? Can deleting of the "mycronfile" disable the cron or do i need to perform "crontab -r mycronfile"... (7 Replies)
Discussion started by: Raynon
7 Replies

9. UNIX for Advanced & Expert Users

Disable and Enable Backspace or Ctrl^H in vi

Could anybody tell me how I can disable or enable the backspace key in vi editor. I would like to feel the essence of the commands of vi editor but as I have the latest version and it is supporting the backspace key. I do it on promp using the command stty erase - This command stops the... (5 Replies)
Discussion started by: mobile01
5 Replies

10. Linux

Enable and disable ttyS0

I have a modem connect it to ttyS0 , in unix sco i know i can disable and enable the port , how can i do this , is there a command that will allow me to do this. **** I'm running Redhat 9 *****External Usrobotics 56k Thanks a lot guys (1 Reply)
Discussion started by: josramon
1 Replies

Featured Tech Videos