HP-UX IPFilter V17.05 Administrator Guide HP-UX 11i v2 and HP-UX 11i v3

IP security classes
TCP ports and port ranges
UDP ports and port ranges
ICMP message type and code
Combination of TCP flags
Network interface
Control incoming TCP connections through Dynamic Connection Allocation (DCA)
Support for NAT, which lets an intermediate HP-UX system act as a translator of IP addresses
and network ports
Send back ICMP error/TCP reset messages for blocked packets
Keep packet state information for TCP, UDP, and ICMP
Keep fragment state information for any IPv4 packet and the same rule to all related fragments
Drop all fragmented traffic if specified by rule
Create extensive logs when required
1.2 Supported and unsupported features
See Appendix A (page 96) for a list of supported and unsupported features, including utilities and
commands distributed with the open source IPFilter product but not supported by HP. This appendix
also lists the network interfaces that are supported and unsupported with HP-UX IPFilter.
1.2 Supported and unsupported features 11