Chinaunix首页 | 论坛 | 博客
  • 博客访问: 90022
  • 博文数量: 14
  • 博客积分: 1545
  • 博客等级: 上尉
  • 技术积分: 205
  • 用 户 组: 普通用户
  • 注册时间: 2007-07-23 18:29
文章分类
文章存档

2011年(3)

2009年(4)

2008年(7)

我的朋友

分类:

2008-06-04 15:29:43

某日按指导书上配置增强Solaris 10的安全性, 运行如下一条命令

/usr/sbin/ndd -set /dev/ip ip_strict_dst_multihoming 1

结果发现scstat不能正常显示IPMP信息了

其他都能显示, 命令长时间停留在下面这行,

-- IPMP Groups --

 

messages显示

[ID 988885 daemon.error] libpnm error: can't connect to PNMd on host2

如果把ip_strict_dst_multihoming  关掉,

/usr/sbin/ndd -set /dev/ip ip_strict_dst_multihoming 0

 

scstat又正常了.

总结: 系统优化也要三思后行, 不能随意更改系统的参数.

以下是该参数的解释.

ip_strict_dst_multihoming and ip6_strict_dst_multihoming

Description

Determine whether a packet arriving on a non-forwarding interface can be accepted for an IP address that is not explicitly configured on that interface. If ip_forwarding is enabled, or xxx:ip_forwarding for the appropriate interfaces is enabled, then this parameter is ignored, because the packet is actually forwarded.

Refer to RFC 1122 3.3.4.2.

Default

0 (loose multihoming)

Range

0 = Off (loose multihoming)

1 = On (strict multihoming)

Dynamic?

Yes

When to Change

If a machine has interfaces that cross strict networking domains (for example, a firewall or a VPN node), set this variable to 1.

Commitment Level

Unstable

阅读(1512) | 评论(0) | 转发(0) |
给主人留下些什么吧!~~