HP-UX IPFilter A.03.05.13 Administrator's Guide: HP-UX 11i v3

Table Of Contents
HP-UX IPFilter on HP-UX 11i Version 3
HP-UX IPFilter Options
Chapter 228
Since enabling HP-UX IPFilter would require bringing down the
networking of the system and then bringing it up, it is recommended to
query the current status (using the -q option) and then use the -e option
to enable HP-UX IPFilter, if it is disabled.
To disable HP-UX IPFilter, enter the following command:
/opt/ipf/bin/ipfilter -d
The state of HP-UX IPFilter, whether enabled or disabled, remains the
same even after the reboot.
WARNING Using /opt/ipf/bin/ipfilter brings down ALL the network
interface cards and therefore the network connectivity of the
machine for a short while when HP-UX IPFilter is being enabled
or disabled (using the -e or -d option).
Unless there is heavy network traffic, this should have no or
little overall effect on existing connections, but the connections
will “hang” for a while. If there is heavy network traffic, it may
not be a good time to enable/disable HP-UX IPFilter firewall. If
the user is running applications like Serviceguard that might
mistake this for network card failure, enabling and disabling of
HP-UX IPFilter must be scheduled so that network outage is not
an issue.
Install HP-UX IPFilter
Unlike on HP-UX 11i version 2, installation of HP-UX IPFilter on
HP-UX 11i version 3 will not involve a system reboot. If the system
already has HP-UX IPFilter and a newer version of HP-UX IPFilter is
being installed, make sure that HP-UX IPFilter is in disabled state
before starting the installation.
The following steps provide an outline of the steps that needs to be
followed to install a newer version of HP-UX IPFilter. For detailed
instruction on how to install HP-UX IPFilter, see Chapter 1, “Installing
and Configuring HP-UX IPFilter.
1. Disable the existing HP-UX IPFilter.
/opt/ipf/bin/ipfilter -d