What is IP source Route ?

Please let me know what is IP source Route and why is it disable for security purpose.
Thanks in advance

Hello Nitin,
Cisco routers normally accept and process source routes. Unless a network depends on it, source routing should be disabled.
Source routing is a technique whereby the sender of a packet can specify the route that a packet should take through the network. As a packet travels through the network, each router will examine the destination IP address and choose the next hop to forward the packet to. In source routing, the "source" (i.e., the sender) makes some or all of these decisions.
Reason for disabling: Attackers can use source routing to probe the network by forcing packets into specific parts of the network. Using source routing, an attacker can collect information about a network's topology, or other information that could be useful in performing an attack. During an attack, an attacker could use source routing to direct packets to bypass existing security restrictions.
Remedy:
Use the 'no ip source-route' command to disable IP source routing on the router. Refer to your router documentation for specific instructions.
Regards,
Mohit 

Similar Messages

  • I am trying to listen BBC radio news from BBC App, but on pressing the button I always get the error "there was an error playing this radio feed". What is the source of this error and how can I remove it?

    I am trying to listen BBC radio news from BBC App, but on pressing the button "live radio" I always get the error "there was an error playing this radio feed". What is the source of this error and how can I remove it?

    That is probably just a generic error message and you might not ever know what is causing it. Assuming that you have been able to play live radio with the app in the past (I know nothing about the app) and assuming that all other Internet related functions (Safari, email, etc.) are working properly on your iPad, quit the app completely and reboot your iPad.
    Go to the home screen first by tapping the home button. Double tap the home button and the recents tray will appear with all of your recent apps displayed at the bottom. Tap and hold down on any app icon until it begins to wiggle. Tap the minus sign in the upper left corner of the app that you want to close. Tap the home button or anywhere above the task bar.
    Reboot the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider if it appears on the screen - let go of the buttons. Let the iPad start up.
    If that fails to resolve the issue, you might want to reboot your router, unplug it for about 30 seconds and then plug it in again.

  • Source Route Bridging/ Translational Bridging

    Has anyone been able to source route bridge on a router with a single token ring interface? I want to bridge traffic between token ring and ethernet. My router 2612 has only one token ring card. What are my options? We are migrating to ethernet one step at a time. Basically this router will replace a bridge. Thx

    What kind of traffic requires Source Route? (SNA). What device hosts are you coming off of?
    The attached shows you how to do it from a Token Ring environment to Ethernet. You need to set up your Source-bridge group and source bridge transparent statements. You need to keep in mind that in a Token Ring environment the bits are in a non-canonical format. In Ethernet they are canonical. ex. A MAc address in non-canonical form is 4000.A26A.8802 Translated to canonical form is 0200.4556.1140. This may seem clear as mudd, but it is a bit flipping process. So when you observe mac addresses in the Tomen Ring world you will see the 4000 macs and in Ethernet you will see the 0200 macs. You need to keep this in mind if you ever have to troubleshoot this.

  • Source Routing - Connection Manager

    Hi,
    I need some help understanding the following source routing function of Connection Manager. The book says:
    "Source routing is used with Connection Manager. CM servers as a proxy server for Oracle Net traffic, enabling Oracle Net traffic to be routed securely though a firewall. Oracle Net treats the addresses as a list of relays, connecting to the first address that then requesting to be passed from the first to the second until the destination is reached. It differs from failover and load balancing in that all addresses are used each time a connection is made".
    I do understand it is possible to configure CM in such a way that it can act as a firewall, accepting and rejecting connections based on certain criteria. What I do not understand is the second part where the addresses are treated as a list of relays. Why would something like this be necessary and how could that be configured in CM.
    Any help would be greatly appreciated....
    Thanks in advance.

    Hi,
    Oracle connection manager enables greater resource utilization for increased scalability,
    multiprotocol connectivity and secure network acces control.
    Example tnsnames.ora:
         CMExample.world =
         (DESCRIPTION=
         (ADDRESS_LIST=
         (ADDRESS=
         (PROTOCOL=tcp)
              (PORT=1610)
                   (HOST=CM_SERVER)
         (ADDRESS=
              (PROTOCOL=tcp)
                   (PORT=1521)
                   (HOST=LSNR_SERVER)
    (CONNECT_DATA=
              (SID=ORCL)
    (SOURCE_ROUTE=yes)
    Example cman.ora:
         cman = (ADDRESS_LIST=
    (ADDRESS=(PROTOCOL=tcp)(HOST=h)(PORT=1610))
    (ADDRESS=(PROTOCOL=tcp)(HOST=h)(PORT=1620))
         cman_profile = (parameter_list=
    (MAXIMUM_RELAYS=1024)
    (LOG_LEVEL=1)               
    (TRACING=no)               
    (RELAY_STATISTICS=yes)     
    (SHOW_TNS_INFO=yes)          
    (USE_ASYNC_CALL=yes)      
    (AUTHENTICATION_LEVEL=1)
    Configuring CM for Network Acces Control(Firewall support):
    Example:
    cman = (ADDRESS_LIST=
    (ADDRESS=(PROTOCOL=tcp)(HOST=h)(PORT=1610))
    (ADDRESS=(PROTOCOL=tcp)(HOST=h)(PORT=1620))
    cman_rules = (rule_list=
    (rule=(src=spcstn)(dst=x)(srv=x)(act=accept))
    "For more information Note:126079.1"

  • Source Routing and Sendmail

    Hi all
    This is probably not directly related to IronPort, but I'm sure you guys might be able to help.
    We installed an IronPort applicane a few months ago and everything works great. Unfortunately, we forward the mails to our internal sendmail server which has to be reachable from the Internet for some legacy stuff. The sendmail box in conjunction with IronPort (smarthost) seems to enable source routing of email addresses, rendering the box an open relay.
    Is there a way to drop all source routed e-mails at sendmail? Based on what I read, IronPort does drop source routed e-mails anyway.
    thx
    reto

    You will need to disable the loose_relay_check option in Sendmail. This option turns off the default behavior of rechecking recipients using the % addressing. For example, if the recipient address is user%site@othersite, the default behavior without the loose_relay_check option is that Sendmail will check if any @othersite is an allowed relay host specified in either class R macro or the access db file. If a site is an allowed relay host, the check_rcpt ruleset strips @othersite and checks user@site for relaying. Sendmail does not recheck user@site if loose_relay_check option is set to ON.

  • What is this? - Routing Protocol is "application"

    Can anyone tell me what this is?
    Routing Protocol is "application"
    I see it when I do a show protocols.  What routing protocol is it?
    Thank you in advanced!

    This is the full output I am confused about.  This is from my ASR 1004:
    #sh ip protocols 
    *** IP Routing is NSF aware ***
    Routing Protocol is "application"
      Sending updates every 0 seconds
      Invalid after 0 seconds, hold down 0, flushed after 0
      Outgoing update filter list for all interfaces is not set
      Incoming update filter list for all interfaces is not set
      Maximum path: 32
      Routing for Networks:
      Routing Information Sources:
        Gateway         Distance      Last Update
      Distance: (default is 4)

  • What are the sources system will pick the document type while creating invo

    hi
    I would like to know how system will pickup the doucment type while creating invoice in vf01.
    i have taken off the fields  f1, f2, from the document type. in billing sub tab.  so  The moment when am creating billing system automatically displaying F2 invoice doucment creation.  What are the sources for this.
    thanks & Regards
    Rack129

    Hi,
    Hope you have maintained u2018Delivery relevant billing type F2u2019 and u2018Order relevant billing type F1u2019 in the billing tab of the Sales document type in VOV8.
    If you create delivery related billing, the system will pick F2. This is controlled in Item category (VOV7). Billing relevance in Business data of Item category decides whether this is delivery related or order related. u2018Au2019 for delivery related billing; u2018Bu2019 for order related billing and so on.
    Item category is determined by this combination: Sales document type + Item cat group + usage + higher level item cat.
    Regards,
    K Bharathi

  • What type of wireless router is the 1st generation time capsule? Is it B, G or N. I'm trying to understand why our wifi signal is a bit erratic. Paul

    what type of wireless router is the 1st generation time capsule? Is it B, G or N? I'm trying to establish whether its causing signal degradation as a result of conflicts with my BT Home Hub router.

    The 1st generation Time Capsule is an 802.11"n" wireless router, but in default settings it produces a signal that is also compatible with "g" and "b" wireless devices.
    If your HomeHub is in close proximity to the Time Capsule and it is also producing a wireless network, either the wireless on the HomeHub or the TIme Capsule should be be disabled to minimize the chances of wireless interference.
    Interference may also be coming from any cordless phones you may have, or another nearby wireless network as well.

  • What is a good router to run a laptop and 2 iphone 5

    I am just wondering what is the best router to use for laptop use and 2 IPhone 5's
    Thanks

    http://www.apple.com/wifi/
    The $99 Express incorporates most of the features of its more expensive sibling.

  • What is Data source? How to create a datasource?

    Hi All,
        anybody could you explain me What is Data source and how to create data source?
    How it is related to BW.
    Points will be rewarded for all the useful answers.
    Priya.

    Hi Priya,
    You can Create DataSource for Different Source systems.
    Chech these URLs.
    http://help.sap.com/saphelp_nw04s/helpdata/en/43/01ed2fe3811a77e10000000a422035/content.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/43/00153831035167e10000000a1553f6/content.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/42/fdccb72aa95277e10000000a1553f7/content.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/43/93dbdbff0b274ee10000000a422035/content.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/43/03b1f4dc636e72e10000000a422035/content.htm
    steps in 'how to delta generic datasource'
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/84bf4d68-0601-0010-13b5-b062adbb3e33
    /message/3471234#3471234 [original link is broken]
    Re: How to create datasource
    <b>Reward points for helpful answers</b>
    Satish

  • What is the source table for repository browser info?

    Hi guys,
    I need to create report for everyday's data refresh, mostly like what repository browser does. So what is the source table for repository browser info? I am in OWB 10gR2. Thanks a lot.

    I believe the runtime audit browser uses the views that start with "RAB" in the control center.
    But it would probably better if you used the Audit Execution views. More information can be found in the "API and Scripting Reference" document...
    http://download.oracle.com/docs/cd/B31080_01/doc/owb.102/b28225/api_2runviews.htm
    In order to get access to the Public views from SQL Plus using a schema other than the control center, I believe you need to grant the ACCESS_PUBLICVIEW_BROWSER sys privilege to each OWB user. Look at Note:434718.1 for more information.

  • HT4910 What is the source of the contact list when I logged in my icloud-from the contact list that I stored in my card or the iphone?

    Q1:What is the source of the contact list when I logged in my icloud-from the contact list that I stored in my card or the iphone?
    Q2:One more thing,when I logged in the icloud with my account ID and password,how can I get another iphone user's contact list in my icloud "contacts".I once used the iphone user 's phone to log in my icloud to get my lost phone,is it normal or unnormal to have this contact list from other?Why can it happened?

    bah, you're right, they can't be seen there.
    But if you want to clear them... How to clear the Local Calendar and Local Contacts databases on the BlackBerry 10 smartphone
    1. If any post helps you please click the below the post(s) that helped you.
    2. Please resolve your thread by marking the post "Solution?" which solved it for you!
    3. Install free BlackBerry Protect today for backups of contacts and data.
    4. Guide to Unlocking your BlackBerry & Unlock Codes
    Join our BBM Channels (Beta)
    BlackBerry Support Forums Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • What is the best router

    Anybody know what is a good router to get a good sync to the exchange with.

    I would have to along with Peggypurecust on this one. Certainly, on my long and aluminium-rich noise-ridden line, Netgear DG834 series routers perform very well. They are also perfect if you need to run RouterStats to gather some data.
    That said, the BT BusinessHub 2-Wire 2700HGV works more consistently for me when there is a lot of interference about. Over the last year or so, I've run the 2-Wire over the winter and a Netgear DG834PN in the summer. Others swear by Billion routers, or those from other manufacturers.
    Your best bet might be to borrow a few from geeky friends and see which works best for you. By and large, routers that allow telnet can be the most versatile.
    More detail here, if you need it
    "To forbid us anything is to make us have a mind for it."
    -- Michel de Montaigne, Essays, 1559

  • What is the best router for mugs connectivity

                       i am looking for best networking institute in India, for optical networking please suggest, have heard about Networkers Zone (http://networkerszone.com/) , however needs suggestion and what is the best router for mugs connectivity.

    For training on the Cisco Optical I would rrecommend Fastlane http://www.fastlane.si/ they would be able to fullfill your training requirements either in India or at another location even at the Cisco Factory in Monza, they can tailor courses to your specific requirements and also do switching and routing courses too, I have know one of the instructors for over 10 years they are very good.
    As far as recommending the best router, that all depends on the application, not what you mean by mugs connectivity, I know what mugs is in English but not sure if thats what you mean or if it is an acronym for something else   in any case if you post in the router section of Net-Pro with your specific requirements I'm sure someone woule be able to help/advise accordingly.

  • How to enable source routing on outgoing packets?

    Hi all
    Perhaps some of you can help me with this. I recently read http://enclaveforensics.com/Blog/files/ … 8d9-5.html about loose source routing, and would like to do the experiment myself in an isolated network dedicated for testing purposes.
    I know how to filter source routed traffic with firewalls (ip-tables), but have no idea of how to enable either loose or strict source routing in the ip-headers for those packets i'm sending out. Maybe there are some kind of setting in some configuration-file? Or are we talking the source code of an application? Kernel compilation setting? Please let me know, if you know how to do it.
    And also please notice this: I've got no malicious intentions. I will only perform this in an isolated network dedicated for testing purposes. So please do not accuse me for beeing a cracker/hacker/whatever...
    Thankyou

    the best way to actually enable it system-wide is to use mangle table of iptables to manually enable the ipv4 options and adding the routing info with each packet, on the other hand, you can create a program with python's scapy that does LSRR and SSRR.
    Last edited by Sin.citadel (2010-07-01 12:00:07)

Maybe you are looking for

  • Some commands don't work in rutorrent/wtorrent

    Hi, I have an odd problem. I'm trying to install rutorrent as a frontend for rtorrent. I don't know too much about apache/php/xmlrpc etc etc. so I have no idea what's wrong or how to go about fixing it. Situation is this: I have managed to set up rut

  • Debugging Automatic Payment Program ?

    Hello, When i make payment thru transactions (f-58 ) i m able to enter into the program thru debugging but when i try uding the automativc payment program (F110) i m unable to eneter the program. Cant we debug the program in case of Automatic Payment

  • Launchpad just closes down when i click on apps??

    cannot click on any apps in launchpad or slie to the next window. its just stuck and cant do anything. anyone know how to fix this?

  • Network Speed Required with VPN

    Hi, I have a customer, he has open an office outside the main company, Only 2-3 user (with all authorization access to B.one) will be connected with VPN. I would like to Know how is the network speed required to use b.one with VPN connections. Thanks

  • Problem creating AVCHD

    I'm trying to create a AVCHD video in Adobe Photoshop Elements 13.1 (20150131.daily.767917). I am choosing "Fit Contents to available space" with an export to "Folder (8.5 GB)". The status is "Space required is more than the Disc capacity" and if I c