Tuesday, January 26, 2010

Disable Ping on AIX & Linux

Disable Ping on AIX & Linux


I had to disable ping for security concerns. Basically I hid my system from ICMP echo discovery.


on AIX

/usr/sbin/genfilt -v 4  -a 'D' -s '0.0.0.0' -m '0.0.0.0' -d '0.0.0.0' -M '0.0.0.0' -g 'y' -c 'icmp' -o 'any' -p '0' -O 'any' -P '0' -r 'B' -w 'B' -l 'N' -t '0' -i 'all' -D 'echo_request'


Easy way is use smitty ipsec4 ,fill required fields.

don't forget to start

smitty ips4_start


on Linux

echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all (on fly and temporary)



add/comment out  net.ipv4.icmp_echo_ignore_all=1 in /etc/sysctl.conf

No comments:

Post a Comment