HP-UX IPFilter A.03.05.13 Release Notes: HP-UX 11i v3
HP-UX IPFilter Release Notes
What’s in This Version
Chapter 1 5
— IP protocol (IP/TCP/UDP)
—IP fragments
—IP options
— IP security classes
— TCP ports and port ranges
— UDP ports and port ranges
— ICMP message type and code
— Combination of TCP flags
—Interface
• Allows control of incoming TCP connections through Dynamic Connection Allocation
(DCA)
• Supports NAT, which lets an intermediate HP-UX system act as a translator of IP
addesses and network ports
• Sends back ICMP error/TCP reset for blocked packets
• Keeps packet state information for TCP, UDP, and ICMP
• Keeps fragment state information for any IP packet, applying the same rule to all
fragments
• Drops all fragmented traffic if specified by rule
• Redirects packets for forensic analysis if specified by rule
• Creates extensive logs when required