HP-UX IPFilter Version 16 Release Notes

1 HP-UX IPFilter Release Notes
Announcement
HP-UX IPFilter, product number B9901AA version 16, is a TCP/IP packet filter suitable for use
as a system firewall. The version strings are as follows:
HP-UX IPFilter Version StringOS Version
A.11.31.16HP-UX 11i v3
A.11.23.16HP-UX 11i v2
HP-UX IPFilter functions as a firewall by examining and limiting packets allowed in and out of
an HP-UX system, which can be either an end node or an IP router. Although HP-UX IPFilter is
a superset of the functionality in the IPFilter 3.5 Alpha 5 open source version of the product
(developed by Darren Reed), HP does not support some of the perimeter firewall features in that
release, such as firewall stealth (fastroute). If you are using features that are not supported by
HP, you can request support from the open source IPFilter web site at the following URL:
http://caligula.anu.edu.au/~avalon
For a complete list of commands and utilities that are not supported by HP, see “Supported and
Unsupported Features” (page 5).
HP-UX IPFilter version 16 is available from the HP Software Depot at the following URL:
http://www.software.hp.com.
What’s in New This Version
HP-UX IPFilter version 16 supports the following new features:
The ipfstat -Q option. This option is supported for HP-UX 11i v3 only and displays the
list of interfaces protected by IPFilter.
Improved throughput and CPU utilization, especially when used with 10 Gigabit Ethernet
interfaces.
Defect fixes, including a fix for a critical defect.
For more information about the defect fixes, see “Fixes in This Version” (page 6) of this
release note.
Known Problems and Workarounds
The startup script for HP-UX IPFilter automatically disables the ip_forward_directed_broadcasts
parameter. This keeps the system from being subjected to broadcast-storm attacks that can
bring down a network.
Supported and Unsupported Features
See the Product Specifications appendix in the HP-UX IPFilter Administrator's Guide for a list of
supported and unsupported features, including utilities and commands distributed with the
open source IPFilter product but not supported by HP. The Product Specifications appendix also
lists the network interfaces that are supported and unsupported with HP-UX IPFilter.
Installation Requirements
This section lists the software and hardware requirements for HP-UX IPFilter version 16.
Announcement 5