A fix is available
APAR status
Closed as program error.
Error description
When applying the "hls_ipsecpermit" (included in the High Security Level) and the HMC IP address is found, aixpert should allow all communications to/from HMC only, but due to an invalid filter mask, it let other IP source address full access to any opened port on VIOS.
Local fix
From oem_setup_env, use lsfilt to check HMC IP is set in rule 2 : # lsfilt -v 4 -n 2 Rule 2: Rule action : permit Source Address : X.Y.Z.AAA (HMC IP) Source Mask : 0.0.0.0 Destination Address : X.Y.Z.BBB (VIOS IP) Destination Mask : 255.255.255.255 <== snip ==> Then you need to fix this, to do so, please run the following : # chfilt -v 4 -n 2 -m 255.255.255.255 # mkfilt -v4 -u
Problem summary
**************************************************************** * USERS AFFECTED: * Systems running the 6100-08 Technology Level with * bos.aixpert.cmds at or between 6.1.8.1 and 6.1.8.18 **************************************************************** * PROBLEM DESCRIPTION: * When applying the "hls_ipsecpermit" (included in the * High Security Level) and the HMC IP address is found, * aixpert should allow all communications to/from HMC only, * but due to an invalid filter mask, it let other IP source * address full access to any opened port on VIOS. **************************************************************** * RECOMMENDATION: * Install APAR IV64436. ****************************************************************
Problem conclusion
Modify source masks in genfilt calls.
Temporary fix
Comments
6100-08 - use AIX APAR IV64436 6100-09 - use AIX APAR IV60830 6100-09 - use AIX APAR IV60830 7100-02 - use AIX APAR IV64260 7100-03 - use AIX APAR IV63187
APAR Information
APAR number
IV64436
Reported component name
AIX 610 STD EDI
Reported component ID
5765G6200
Reported release
610
Status
CLOSED PER
PE
YesPE
HIPER
NoHIPER
Submitted date
2014-09-02
Closed date
2014-09-02
Last modified date
2016-05-11
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX 610 STD EDI
Fixed component ID
5765G6200
Applicable component levels
R610 PSY U867335
UP15/01/18 I 1000
PTF to Fileset Mapping
U867335 bos.aixpert.cmds 6.1.8.19
[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSLLZP","label":"AIX Standard Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSAUMY","label":"IBM AIX Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11Q","label":"AIX 6.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"APARs - AIX 7.1 environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
11 May 2016