HP-UX IPFilter V17.05 Administrator Guide

5 Configuring and Loading Dynamic Connection Allocation
(DCA) Rules
This chapter describes Dynamic Connection Allocation (DCA). DCA helps protect and mitigate
against DOS attacks where an attacker attempts to overload a system with TCP connection
requests. DCA uses stateful packet inspection to limit the number of incoming TCP connections
to a system.
This chapter describes DCA keywords and syntax. It also contains procedures for changing DCA
rules dynamically and setting DCA mode at startup.
NOTE: On HP-UX 11i v1 systems, DCA is not supported with IPv6 addresses.
This chapter contains the following sections:
“DCA with HP-UX IPFilter” (page 50)
“Overview: DCA Functionality” (page 50)
“DCA Rules Configuration Files” (page 50)
“DCA Rule Syntax and Keywords” (page 51)
“DCA Rule Conditions” (page 51)
“keep limit: Limiting Connections” (page 51)
“return-rst: Returning RESET Packets” (page 52)
“cumulative: Limiting Cumulative Connections” (page 52)
“log limit: Logging Exceeded Connections” (page 52)
“log limit freq: Log Frequency ” (page 53)
“Loading and Modifying DCA Rules” (page 55)
“Updating keep limit Rules” (page 55)
Adding New keep limit Rules” (page 56)
“Integrating keep limit Rules” (page 56)
“Extracting an Individual Rule from a Subnet Rule” (page 57)
“Enabling and Disabling DCA” (page 58)
“Enabling and Disabling DCA Using ipf” (page 58)
“Configuring IPFilter to Enable DCA at System Startup Time” (page 58)
“Using IPFilter Utilities with DCA” (page 58)
“keep limit Rules and Rule Hits” (page 59)
“Monitoring and Allocating Memory for DCA Data” (page 60)
49