HP-UX IPFilter v18.21 Administrator Guide HP-UX 11i v3 (761995-001, March 2014)

TCP ports and port ranges
UDP ports and port ranges
ICMP message type and code
Combination of TCP flags
Network interface
Control of incoming TCP connections through Dynamic Connection Allocation (DCA)
Support for NAT, which enables an intermediate HP-UX system to act as a translator of IP
addresses and network ports
Return of ICMP error/TCP reset messages for blocked packets
Maintenance of packet state information for TCP, UDP, and ICMP
Maintenance of fragment state information for any IPv4 packet and the same rule to all related
fragments
Capability to drop all fragmented traffic if specified by rule
Creation of extensive logs when required
Supported and unsupported features
See Appendix A (page 102) for a list of supported and unsupported features, including utilities and
commands distributed with the open source IPFilter product but not supported by HP. This appendix
also lists the network interfaces that are supported and unsupported with HP-UX IPFilter.
12 Overview