On Tuesday, 01/08/2008 at 03:09 EST, Pieter Harder
<[EMAIL PROTECTED]> wrote:
> I would even say this is a security exposure. A class G user can find
out what
> another user's macid is on a layer2 switch, and then play all kind of
mischief
> with it.

We are aware of the requirement to prevent two users on the same VSWITCH
from talking to each other.

Restricting the details of the VSWITCH simply makes it more difficult for
the guest to be configured correctly.  I mean, does the sysprog *really*
want to be involved in every "guest A can't ping guest B" quandry?

And if I wanted to, I'd just start ARPing for different IP addys and see
what responses I get.  Not have the QUERY output would slow me down for a
few minutes.

Alan Altmark
z/VM Development
IBM Endicott

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to