HP-UX IPFilter Version 15.01 Administrator's Guide

5 Configuring and Loading Dynamic Connection Allocation
(DCA) Rules
This chapter describes Dynamic Connection Allocation (DCA). DCA helps protect and mitigate
against DOS attacks where an attacker attempts to overload a system with TCP connection
requests. DCA uses stateful packet inspection to limit the number of incoming TCP connections
to a system.
This chapter describes DCA keywords and syntax. It also contains procedures for changing DCA
rules dynamically and setting DCA mode at startup.
NOTE: On HP-UX 11i v1 systems, DCA is not supported with IPv6 addresses.
This chapter contains the following sections:
“DCA with HP-UX IPFilter” (page 48)
“Overview: DCA Functionality” (page 48)
“DCA Rules Configuration Files” (page 48)
“DCA Rule Syntax and Keywords” (page 49)
“DCA Rule Conditions” (page 49)
“keep limit: Limiting Connections” (page 49)
“return-rst: Returning RESET Packets” (page 50)
“cumulative: Limiting Cumulative Connections” (page 50)
“log limit: Logging Exceeded Connections” (page 50)
“log limit freq: Log Frequency ” (page 51)
“Loading and Modifying DCA Rules” (page 53)
“Updating keep limit Rules” (page 53)
Adding New keep limit Rules” (page 54)
“Integrating keep limit Rules” (page 55)
“Extracting an Individual Rule from a Subnet Rule” (page 55)
“Enabling and Disabling DCA” (page 56)
“Enabling and Disabling DCA Using ipf” (page 56)
“Configuring IPFilter to Enable DCA at System Startup Time” (page 56)
“Using IPFilter Utilities with DCA” (page 56)
“keep limit Rules and Rule Hits” (page 57)
“Monitoring and Allocating Memory for DCA Data” (page 58)
47