HP-UX IPFilter V17.05 Administrator Guide

In this example, every valid packet is entered into the state table before the blocking rules are
processed. To further protect the system, log initial SYN packets to detect SYN scans.
3.5 Protocol Options: TCP Flags, IP Options and Fragments, ICMP Types and State Information 37