HP-UX 11i Version 2 December 2005 Release Notes

Table Of Contents
Security
HP-UX IPFilter
Chapter 8
165
userdb (4)
•Other documentation:
HP-UX 11i Security Containment documentation, available at
http://docs.hp.com/en/internet.html#Security%20Products
See also “HP-UX Role-Based Access Control” on page 166.
Obsolescence
Not applicable.
HP-UX IPFilter
The security product, HP-UX IPFilter version A.03.05.12, provides system firewall
capabilities by filtering IP packets to control traffic in and out of a system.
Summary of Change
HP-UX IPFilter version A.03.05.12 contains defect fixes and minor enhancements. It
also includes the following new features and major enhancements:
•NOSYNC pre-enablement
RPC services enhancement
For more information on defect fixes, see the HP-UX IPFilter A.03.05.12 Release Notes,
available at http://docs.hp.com/en/internet.html#IPFilter.
No Sync Support
HP-UX IPFilter A.03.05.12 is pre-enabled to support the NOSYNC method of Streams
synchronization.
In addition to IPFilter, the complete NOSYNC solution involves changes in Streams,
Transport, and DLPI. Transport Optional Upgrade Release (TOUR) 3.0 and NOSYNC
DLPI are required to realize the performance gain associated with the NOSYNC
enhancement. Installing the TOUR 3.0 software and the HP-UX 11i v2 DLPI patch
(PHNE_33429) satisfies the dependency requirements.
For more information, see the Transport Optional Upgrade Release (TOUR) 3.0 Release
Notes, available at http://docs.hp.com.
RPC and IPFilter
Remote Procedure Call (RPC) services do not use fixed port numbers, making it difficult
to write IPFilter rules to filter RPC traffic. A new set of scripts is included with this
release, which dynamically discover RPC ports and adds rules based on a configuration
file.
For more information, see the HP-UX IPFilter A.03.05.12 Administrator’s Guide,
available at http://docs.hp.com/en/internet.html#IPFilter.