Can't access /dev/ip with ndd -get /dev/ip \?

Hi all,
I am currently assesing the feasibility of running our software on Solaris 10 zones. I have run into a bit of a snag. The designers here tell me that the require the command ndd -get /dev/ip to work.
I have configured the zone with the device:
zonepath: /export/home/zone2
autoboot: true
pool:
inherit-pkg-dir:
        dir: /lib
inherit-pkg-dir:
        dir: /platform
inherit-pkg-dir:
        dir: /sbin
inherit-pkg-dir:
        dir: /usr
net:
        address: 47.135.214.77
        physical: bge0
device
        match: /dev/ipI am able to see /dev/ip in the zone
# ls -l /dev/ip
crw-rw-rw-   1 root     sys        3,  0 Jan 21 07:09 /dev/ipEverything looks good.
However, I cannot execute the command ndd
# ndd -get /dev/ip \?
open of /dev/ip failed: Permission denied
Is this expected behaviour or is there something that I should do to confgure this in the zone?
incidently, /dev/tcp is accessible from the zone:
# ndd -get /dev/tcp \?
?                             (read only)
tcp_time_wait_interval        (read and write)
tcp_conn_req_max_q            (read and write)
tcp_conn_req_max_q0           (read and write)
:Thanks,
Rich

Hello,
Yes a zone can't open /dev/ip because otherwise the zone could send handcrafted IP packets with the global zone's source address etc.
There are two workarounds:
- use <code>ndd -get /dev/arp {ip_ndd_variable}</code>
- replace the following line in /etc/security/device_policy :
<code>ip read_priv_set=net_rawaccess write_priv_set=net_rawaccess</code>
with:
<code>ip read_priv_set=net_icmpaccess write_priv_set=net_icmpaccess</code>
But beware, this one allows the zone to send rogue packets as described above.
Just being curious, which IP ndd variables do you want to look at from within the zone? We'd like to provide a better interface for applications to access those parameters.
Blaise

Similar Messages

  • Can't access my iMessages with my apple Ida

    Can't access my iMessages with my apple Id

    Most Apple stores will replace your screen/digitizer for US $149. Why don't you call your local store to see if they offer this service, & if they do, make an appointment & get your phone fixed.

  • After Mac OS X 10.6.3 upgrade can't access Yahoo mail and repeatedly get message ""Sorry, we are over capacity. Please wait a moment and try again." Help, please,

    After Mac OS X 10.6.3 upgrade can't access Yahoo mail and repeatedly get message ""Sorry, we are over capacity. Please wait a moment and try again." Help, please.

    Did you run all the software updates after the 10.6.3 update, especially this one which will bring you up to 10.6.8.
    Mac OSX 10.6.8 V1.1 Combo update
    Run software update, starting with the one above.
    Then call your provider and ask them what is going on. They have probably changed POP to IMAP, 10.6.8 supports IMAP

  • Can't access home sharing with current Apple ID info

    I can't access Home Sharing with my current Apple ID info. But I can access the discussions forum with my current Apple ID info though. This is very strange. Anyone having this problem? I tried turning on the Home Sharing function in the iTunes Advanced menu, but to no avail because it won't accept my current Apple ID info. I have the ATV2 model.
    Message was edited by: Charles Swaim

    My ATV 2 can get view movies from Netflix and Youtube without a problem, but when there's a need to use my Apple ID for the Home Sharing function -- from either my Mac or the ATV 2 -- it won't work. It's weird how my Apple ID can access this discussion group without a problem, but can't engage the Home Sharing. I'll see if there's another update available for the ATV 2. Hopefully that might help. Many thanks for trying to help.

  • Hi, I have imac mac os 10.6.7, I can't access to internet with my ipod  touch using my imac airport...what's wrong? my ipod tells me is connected and airport is active...so? what should I do?

    Hi,
    I have imac mac os 10.6.7, I can't access to internet with my ipod  touch using my imac airport...what's wrong? my ipod tells me is connected and airport is active...so? what should I do?

    right, figured it out. had to put it in disk mode, then reconnect, then it was recognized, then i restored and put everything back onto it. hope this helps anyone else who has a similar problem

  • I'm running logic pro 8.0.2 on Leopard 10.5.8. I've recorded an evening of live music, the cut the recording into songs using one audio file folder. When working on an individual song, I can't access the sampler.  I get the message "nothing to display"

    I'm running logic pro 8.0.2 on Leopard 10.5.8. I've recorded an evening of live music, then cut the recording into songs using one audio file folder ad multiple song files. When working on an individual song, I can't access the sampler.  I get the message "nothing to display" or "no region or audio file selected"  After much research on the web, I believe this is a permanent bug.  Does anyone have a good work-around for this type of work.  We record live 16T band rehearsals constantly and would love to be able to break individual songs out of the large file and be able to use the sampler.  Thanks in advance for your ideas!  Cheers.

    Another thing - if I copy one of the tracks to another track, then the sample editor works on the copied track.  I don't want to have to copy 16 tracks to new tracks to be able to use the sample editor on a project.  Thanks again.

  • Can i access swf files with your product?

    can i access swf files with dreamweaver?

    You will need Flash as well as Dreamweaver.
    Follow these instructions http://help.adobe.com/en_US/dreamweaver/cs/using/WSc78c5058ca073340dcda9110b1f693f21-7ad0a .html

  • I can't access Facebook. I keep getting the "Firefox has detected that the server is redirecting the request for this address in a way that will never complete". I have cleared cache, cookies, history, offline storage. Nothing has worked.

    can't access Facebook. I keep getting the "Firefox has detected that the server is redirecting the request for this address in a way that will never complete". I have cleared cache, cookies, history, offline storage. Nothing has worked.

    Start Firefox in [[Safe Mode]] to check if one of your add-ons is causing your problem (switch to the DEFAULT theme: Tools > Add-ons > Themes).
    See [[Troubleshooting extensions and themes]] and [[Troubleshooting plugins]]

  • I can't access my camera with the camera button.  Only able to make videos.

    I can't access my camera with the camera button.  Only able to make videos.

    Could you have accidentally toggled the photo to video? In the lower right (usually) corner there's a little icon that has both film and video camera and a tiny slider between them. That's how you switch from one to the other.

  • I can't access the app store - I get the following messages - error 1004 or 100 or 4 or unknown error - help!!!

    I can't access the app store - I get the following messages - error 1004 or 100 or 4 or unknown error - help!!!
    I've disabled the firewalls, the virus protection, the application protection - nothing helps.

    I'd maybe try doing a search for Safari on your iPad first (swipe to the left to search). If it shows up in that search you can go to Settings > General > Reset and choose 'reset home screen layout' which will put it back where it would be by default.
    All else fails? Restore it.

  • My laptop had to be reimaged and all software and programs were taken off.  I installed itunes again but can't access my library.  I get an error message "the folder itunes cannot be found or created and is required.  The default location for this folder

    I can't access my itunes music on my laptop after having it re-imaged.  I installed itunes again but can't access the music folder.  I get the following message when I click to open itunes:  "The folder itunes cannot be found or created, and is required.  The default location for this folder is the Music folder.
    I have an iPad2, and iPad mini, and an iPhone5 with a different number of songs on each.  I want to sync everything -- should have close to 800 songs.  Tried to get support from Apple but would be charged for help. 

    I have a Windows 7 operating system my computer runs from.

  • I can't access the internet with Firefox on my computer (Windows 7 PC). I have used Firefox as my browser for 1 year but 5 days ago it stopped working even though Internet Explorer worked fine. I can't solve the problem and need some help.Randy Brown

    September 26, 2011
    Dear Mozilla,
    I am having some difficulty accessing the internet with Firefox on one of my PC computers. I normally use Mozilla Firefox as my web browser and google is my homepage and gmail is my email system. The operating system is Windows 7. For over a year this system worked perfectly but a few days ago it stopped working. When I launch Firefox now I get the message that that website (www.google.com) is unavailable. In fact, I can’t access any website and I am blocked from the internet entirely within Firefox. My internet connection is fine because Internet Explorer works fine. I can access google and any other website within that web browser. I have investigated all the security issue I can manage and found no smoking gun. I’ve tried uninstalling and reinstalling Firefox to no avail. Is Windows 7 compromising the effectiveness of Firefox? Any suggestions or other assistance you can offer would be appreciated.
    Sincerely,
    Randy Brown
    [email protected]

    You only have to clone your mac when using certain cable modem.  You don't clone your mac when using dsl.
    Greetings from Northern Ontario, Canada

  • My Time Capsule hard drive shows up in Finder, but I can't access the disk.  I get a connection failed message.

    I can not access my Time Capsule from the Finder.  This was working, but on 12/25/2011, the disk can no longer be accessed.  It shows up in the Finder, but when I try to connect, I get a "Connection Failed" message.  If I cycle the power, it works for a little while and then fails again.

    hello
    No i'm connect via ethernet (cable) with TC. The problem is when I try to connect to my TC when I'm away from home like for ex. using a free wi fi spot!! Well in this case the icon appear on my Finder but refuse to connet!! ( connection faild ).

  • User can't access a PDF with Forms

    On a website, we have a main menu PDF with a list of bookmarks linking to individual user manual PDFs.  When a user tries to access a user manual  PDF with forms in it, they get the error "There was an error processing a page. There was a problem reading this document (118)." The user dosen't appear to have any problem opening a PDF that doesn't contain forms. 
    The user is using Reader 10.1.3 and Internet Explorer 8.0.6001.19328.  This user cannot access the PDFs with forms when given a direct link to the file either. However, if the user is sent the PDF file they can open it with Reader and in their browser.  I'm stumped.  Does any body know what's going on here?

    Is there a browser setting that can affect if a PDF opens? Something in security, perhaps? I've looked around and don't see anything obvious that could allow/disallow opening a PDF file that contains form fields.
    Jeanie

  • Can't access google calendar with parental controls on

    We are trying to give our daughter accesss to the family's Google calendar.  In the parental controls we have "try to limit adult websites" as the selection.  With this on, she is not able to log into the calendar - it gives a message that says something about not being able to establish a secure connection.  She can go on the Google homepage without problem and search, etc. - but she can't access the Google sign-in or the calendar.
    When we change the parental controls setting to "allow all websites" she can log onto the calendar without any problem.
    We also tried adding the various google web address strings under the "customize" tab for "always allow these sites" while still leaving the "try to limit adult websites" as the overall setting.  Even with the specific sites approved - she still can't access the calendar.
    What's up??  Isn't there a way we can allow her to see the calendar without having to give her unecessary exposure to anything on the net?

    So after I made my original post above I continued searching the forums and found the answer below.  It refers to Googla Mail but their solution worked just as well for Google Calendar.  Who knew it would be so simple.  I just went into "always allow these sites" and put in the 1e100.net and it worked like a champ!  The adult sites are still screened out but she can now access Google without any issue.
    atobteam
    Re: Why can't I access Gmail anymore when internet restrictions are in plac 
    Apr 10, 2010 1:52 PM (in response to atobteam)
    Finally!!!!! This solution works! Yea!  There are two scenarios I know of: 1. If you have users for whom under "Parental Controls/Content" you've chosen "Allow access only to these websites" (they can only get to the websites that are bookmarked by you) and if Google Mail was already a bookmark, then just do this: click the plus sign below the list in "Parental Controls/Content/Allow access only to these websites", and choose "Add Bookmark." On the pop-up, name the site "goog" or anything you want; then type in: 1e100.net in the box asking for an address. This will produce a new bookmark (named "goog" or whatever you've chosen), but will in effect just be a dummy or slave bookmark that you'll never use, but it'll allow you to get to your user's google mail sign in page by hitting the old google mail bookmark he or she used to hit. Second scenario (I have both scenarios in my home): if you have users for whom under "Parental Controls/Content" you've chosen "Try to Limit Access to Adult Websites Automatically", click the "Customize" button and then on the top of the pop-up, under "Always Allow These Websites," click the plus button and then add: 1e100.net . Then click OK. This user will now be able to get to his or her google mail sign in page. 

Maybe you are looking for

  • Why can I not send email from my mail on my computer?

    I am receiving mail into my inbox, but cannot send out?  anyone have any ideas?

  • RFC call to other R/3 system

    I have to execute ztransaction from BW to R/3. User don't want to logon to R/3. REPORT  ZRFC. data : ZDEST like RFCDES-RFCDEST. data : ztcode like TSTC-TCODE. zdest = 'TEST1200'. ztcode = 'ZME21'. CALL FUNCTION ZTCODE DESTINATION   ZDEST. or call tra

  • CS4 does not play audio from .MTS file...only hash

    I have CS4 on Windows 8 64 bit and cannot get anything but hash from the audio....thoughts.

  • IWeb Domain and MobileMe

    I have two mobile me accounts and maintain two websites. I back up the domain(s) on removable hard drives and usually work on the site from a variety of office and home computers via the removable HD, save domain to removable HD and then upload being

  • FP70- Reporting of Incorrect Bank Data

    Hi Under SAP ISU FICA, transaction FP70 can be used to process the ADDACS file received from banks in UK. However SAP does not allow creation of manual lot in FP70. Can someone recommend how can we create a incorrect bank data lot and test the config