HP-UX IPFilter Version A.03.05.14 Administrator's Guide
Rules and Keywords
Chapter 222
It contains the following sections:
• IPFilter Configuration Files
• Basic Rules Processing
• IPFilter Keywords
— pass and block: Controlling IP Traffic
— in and out: Bidirectional Filtering
— quick: Optimizing IPFilter Rules Processing
— on: Filtering by Network Interfaces
— from and to: Filtering by IP Addresses and Subnets
— log: Tracking Packets on a System
— proto: Controlling Specific Protocols
— opt and ipopts: Filtering on IP Options
— icmp-type: Filtering ICMP Traffic by Type
— port: Filtering on TCP and UDP Ports
— keep state: Protecting TCP, UDP, and ICMP Sessions
— flags: Tight Filtering Based on TCP Header Flags
— keep frags: Letting Fragmented Packets Pass
— with frags: Dropping Fragmented Packets
— with short: Dropping Short Fragments
— return-rst: Responding to Blocked TCP Packets
— return-icmp: Responding to Blocked ICMP Packets
— dup-to: Drop-Safe Logging
•NAT Keywords
— map and portmap: Basic NAT
— bimap: Bidirectional Mapping
— rdr: Redirecting Packets
— map-block: Mapping to a Block of Addresses