A fix is available
APAR status
Closed as program error.
Error description
When applying the "hls_ipsecpermit" (included in the High Security Level) and the HMC IP address is found, aixpert should allow all communications to/from HMC only, but due to an invalid filter mask, it let other IP source address full access to any opened port on VIOS.
Local fix
From oem_setup_env, use lsfilt to check HMC IP is set in rule 2 : # lsfilt -v 4 -n 2 Rule 2: Rule action : permit Source Address : X.Y.Z.AAA (HMC IP) Source Mask : 0.0.0.0 Destination Address : X.Y.Z.BBB (VIOS IP) Destination Mask : 255.255.255.255 <== snip ==> Then you need to fix this, to do so, please run the following : # chfilt -v 4 -n 2 -m 255.255.255.255 # mkfilt -v4 -u
Problem summary
**************************************************************** * USERS AFFECTED: * Systems running the 7100-03 Technology Level with the * bos.aixpert.cmds fileset at 7.1.3.0 or 7.1.3.15 **************************************************************** * PROBLEM DESCRIPTION: * When applying the "hls_ipsecpermit" (included in the * High Security Level) and the HMC IP address is found, * aixpert should allow all communications to/from HMC only, * but due to an invalid filter mask, it let other IP source * address full access to any opened port on VIOS. **************************************************************** * RECOMMENDATION: * Install APAR IV63187. ****************************************************************
Problem conclusion
Modify source masks in genfilt calls.
Temporary fix
Comments
6100-08 - use AIX APAR IV64436 6100-09 - use AIX APAR IV60830 6100-09 - use AIX APAR IV60830 7100-02 - use AIX APAR IV64260 7100-03 - use AIX APAR IV63187
APAR Information
APAR number
IV63187
Reported component name
AIX V7.1
Reported component ID
5765H4000
Reported release
710
Status
CLOSED PER
PE
YesPE
HIPER
NoHIPER
Submitted date
2014-08-04
Closed date
2014-08-04
Last modified date
2016-05-11
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX V7.1
Fixed component ID
5765H4000
Applicable component levels
R710 PSY U865847
UP15/05/19 I 1000 Ø
PTF to Fileset Mapping
U865847 bos.aixpert.cmds 7.1.3.45
U862116 bos.aixpert.cmds 7.1.3.30
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"AIX 7.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
11 May 2016