HP-UX IPFilter A.03.05.13 Administrator's Guide: HP-UX 11i v3
Table Of Contents
- HP-UX IPFilter Version A.03.05.13 Administrator's Guide
- Legal Notices
- Table of Contents
- Preface: About This Document
- 1 Installing and Configuring HP-UX IPFilter
- Overview of HP-UX IPFilter Installation
- Step 1: Checking HP-UX IPFilter Installation Prerequisites
- Step 2: Loading HP-UX IPFilter Software
- Step 3: Determining the Rules for IPFilter
- Step 4: Adding Rules to the Rules Files
- Step 5: Loading IPFilter and NAT Rules
- Step 6: Verifying the Installation and Configuration
- Kernel Tunable Parameters
- Supported and Unsupported Interfaces
- Troubleshooting HP-UX IPFilter
- 2 HP-UX IPFilter on HP-UX 11i Version 3
- 3 Rules and Keywords
- IPFilter Configuration Files
- Basic Rules Processing
- IPFilter Keywords
- pass and block: Controlling IP Traffic
- in and out: Bidirectional Filtering
- quick: Optimizing IPFilter Rules Processing
- on: Filtering by Network Interfaces
- from and to: Filtering by IP Addresses and Subnets
- log: Tracking Packets on a System
- proto: Controlling Specific Protocols
- opt and ipopts: Filtering on IP Options
- icmp-type: Filtering ICMP Traffic by Type
- port: Filtering on TCP and UDP Ports
- keep state: Protecting TCP, UDP, and ICMP Sessions
- flags: Tight Filtering Based on TCP Header Flags
- keep frags: Letting Fragmented Packets Pass
- with frags: Dropping Fragmented Packets
- with short: Dropping Short Fragments
- return-rst: Responding to Blocked TCP Packets
- return-icmp: Responding to Blocked ICMP Packets
- dup-to: Drop-Safe Logging
- NAT Keywords
- 4 Dynamic Connection Allocation
- 5 Firewall Building Concepts
- Blocking Services by Port Number
- Using Keep State
- Using Keep State with UDP
- Using Keep State with ICMP
- Logging Techniques
- Improving Performance with Rule Groups
- Localhost Filtering
- Using the to
- Creating a Complete Filter by Interface
- Combining IP Address and Network Interface Filtering
- Using Bidirectional Filtering Capabilities
- Using port and proto to Create a Secure Filter
- 6 HP-UX IPFilter Utilities
- 7 HP-UX IPFilter and FTP
- 8 HP-UX IPFilter and RPC
- 9 HP-UX IPFilter and IPSec
- 10 HP-UX IPFilter and Serviceguard
- A HP-UX IPFilter Configuration Examples
- B HP-UX IPFilter Static Linking
- C Performance Guidelines
- Index

192
H
high availability
, 137
I
ICMP
error status messages
, 77
filtering on, 41
keeping state with, 77
icmp-type keyword, 41
in keyword, 36
inactive rules list, 11
installation
checklist, 3
IPFilter on HP-UX 11i v3, 28
loading software, 5
prerequisites, 4
verifying, 13
integrating keep limit rules, 68
interfaces
supported, 19
unsupported, 19
interface-specific filtering, 37
interoperability
IPSec
, 127
IP address
filtering by
, 38
limiting connections by, 57
ipf, 91
-A option, 11
adding rules, 10
-D option, 92
-E option, 92
-f option, 10
-Fa option, 11, 91
-Fi option, 91
-Fo option, 91
-I option, 11, 91
loading rules with, 8
-m d option, 69, 92
-m e option, 69, 92
-m option, 92
-m q option, 69, 92
-m t option, 69, 92
-Q option, 92
-s option, 11, 91
-V option, 13
-Z option, 91
ipf module, 176
ipf.conf, 10
adding rules, 8
bootup start, 10
syntax in, 34
ipfboot, 10, 22
IPFilter
disabling, 27
enabling, 27
removing, 29
ipfilter, 27
-d option, 27
-e option, 27
-q option, 27
IPFilter modules
ipf
, 176
pfil, 176
ipfstat, 94
-B option, 95
-h option, 94
-i option, 13, 94
-L option, 94, 98
-n option, 96
-o option, 13, 94
-r option, 95, 100
-s option, 97
-sl option, 97
-v option, 95
-v-L option, 94, 99
ipftest, 105
-i option, 105
-r option, 105
ipl_buffer_sz, 16
ipl_logall, 17
ipl_suppress, 17
ipmon, 22, 23, 78, 101
-A option, 101
-a option, 101
-F option, 101
-n option, 101
-o option, 101
-r option, 60, 101
ipnat, 109
-C option, 109
-F option, 109
-f option, 109
-l option, 109
-r option, 109
ipnat.conf
adding rules, 8
ipopts keyword, 40