Greetings all,
Had an interesting one this morning. My ACP interface decided to do two things:
1. Turn WINS on (i've got it shut off in /etc/rc)
2. Register with my WINS servers
Fortunately I caught it before we had any issues; however, I'd like to avoid this in the future. (A simple ifconfig e0a -wins and a clean up of dns is all it took.)
What was I doing this morning? Verifying my documentation by checking aggregate disk layout using SM2.0rc1. I tried repeating my steps to see if the wins flag went away a second time but no luck. I see no-one else in the systems this morning.
So I've got an interface that "shouldn't" have gotten out into the wild and an ifconfig flag that "shouldn't" have changed (according to support.)
Has anyone seen either their ACP connection information get out into the wild or an ifconfig flag randomly change? Alternately, any recommendations on forensics? I've looked through messages and acp_master and did not see any obviously suspicious.