Too much ARP for a zone

Hello all,

Sitting in a container,

I still can guess the IP and MAC addresses of all active NICs

on the physical box, as well as grasp some information of it's peers.

Is it a feature? :-)

Then, I should have a choiсe to switch it off, shouldn't I?

Thanks,

Andrei

[Connected to zone 'smbd' pts/18]

Last login: Wed Oct 4 11:49:05 on pts/18

Sun Microsystems Inc.SunOS 5.11snv_44 October 2007

#

#

# uname -a

SunOS smbd 5.11 snv_44 sun4u sparc SUNW,Sun-Blade-1000

#

# ps -eflo zone | grep gobal | wc -l

0

#

# ifconfig -a

lo0:5: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1

inet 127.0.0.1 netmask ff000000

ce2:1: flags=1100803<UP,BROADCAST,MULTICAST,ROUTER,IPv4> mtu 1500 index 3

inet 192.168.1.204 netmask ffffff00 broadcast 192.168.1.255

#

# arp -a

Net to Media Table: IPv4

DeviceIP AddressMaskFlagsPhys Addr

-- --

ce3177.1.1.201 255.255.255.255 SP00:03:ba:b1:9d:73

ce3177.1.1.203 255.255.255.255 SP00:03:ba:b1:9d:73

ce3177.1.1.202 255.255.255.255 SP00:03:ba:b1:9d:73

ce3177.1.1.205 255.255.255.255 SP00:03:ba:b1:9d:73

ce3177.1.1.206 255.255.255.255 SP00:03:ba:b1:9d:73

ce3177.1.1.17255.255.255.255 SP00:03:ba:b1:9d:73

ce2smbd255.255.255.255 SP00:03:ba:b1:9d:72

ce0196.1.1.99255.255.255.25500:30:4f:32:37:18

eri0199.1.1.1255.255.255.255 SP00:03:ba:0f:f0:95

ce0196.1.1.15255.255.255.25504:4b:80:80:80:03

ce0196.1.1.17255.255.255.255 SP00:03:ba:b1:9d:70

eri0219.160.42.179255.255.255.255 SP00:03:ba:0f:f0:95

eri0219.160.42.178255.255.255.255 SP00:03:ba:0f:f0:95

eri0219.160.42.181255.255.255.255 SP00:03:ba:0f:f0:95

eri0219.160.42.180255.255.255.255 SP00:03:ba:0f:f0:95

eri0219.160.42.182255.255.255.255 SP00:03:ba:0f:f0:95

eri0213.160.42.177255.255.255.25500:02:cf:02:5a:dd

eri0224.0.0.0240.0.0.0SM01:00:5e:00:00:00

ce3224.0.0.0240.0.0.0SM01:00:5e:00:00:00

ce2224.0.0.0240.0.0.0SM01:00:5e:00:00:00

ce0224.0.0.0240.0.0.0SM01:00:5e:00:00:00

#

#

#

[2227 byte] By [rygoff] at [2007-11-26 10:34:08]
# 1

> Sitting in a container,

> I still can guess the IP and MAC addresses of all

> active NICs

> on the physical box, as well as grasp some

> information of it's peers.

Yes.

> Is it a feature? :-)

> Then, I should have a choiсe to switch it off,

> shouldn't I?

I guess it would be nice, but complete and utter lockdown of any bit of information transfer probably wasn't a design goal. I don't believe that knowledge of the MAC/IPs is considered a problem.

I think the "Solaris Internals" book mentioned something similar to this. I don't have my copy nearby to check if it was talking about network addresses or if it discussed some other low-bandwidth leaking.

--

Darren

Darren_Dunham at 2007-7-7 2:43:15 > top of Java-index,Solaris Operating System,Solaris 10 Features...