Network Security Features of HP-UX 11i v1 and 11i v2

Network Security Features of HP-UX 11i
Page 13
Return messages in response to blocked packets: Sends back ICMP error/TCP reset for blocked
packets. This helps keep attackers from realizing their packets have been explicitly blocked.
Keep state functionality: Enforces packet blocking based on session state for TCP, UDP, and ICMP.
IP fragment control: Keeps fragment state information for any fragmented IP packet, applying the
same rule to all fragments, or drops all fragmented traffic if specified by rule.
Logging and analysis: Creates extensive logs when required, collects statistics and ability for
extensive logging, and redirects packets for forensic analysis if specified by rule.