HP-UX 11i Version 2 Installation and Update Guide, May 2005

Choosing an Installation Method
Security Considerations
Chapter 366
Table 3-7 Additional Sec30DMZ Install-time Security Settings
1
Category Actions
IPFilter
Configuration
2
Includes all IPFilter settings in Table 3-6 and:
Block incoming HIDS agent connections
3,4
Block incoming WBEM connections
5
Block incoming web admin connections
Block incoming web admin autostart connections
Block all traffic except HP-UX Secure Shell
1. Applies all security configuration settings in Table 3-5 and Table 3-6
2. IPFilter rules are applied via a custom rules file located at
/etc/opt/sec_mgmt/bastille/ipf.customrules
3. Settings applied only if software is installed
4. HP-UX Host IDS is a selectable software bundle and only available for commercial
servers
5. WBEM is required for several HP management applications including
Servicecontrol Manager and ParMgr