| United States-English |
|
|
|
![]() |
HP-UX IPFilter Version A.03.05.12 Administrator's Guide: HP-UX 11.0, HP-UX 11i version 1,HP-UX 11i version 2 > Chapter 4 Firewall
Building Concepts Using the to Keyword to Capture Blocked Packets |
|
You can use the to keyword apart from the from keyword. If you want to block a packet, you can use the to keyword to push the packet past the normal routing table and force it to go out on a different interface. For example:
This rule blocks incoming packets, but also forces them over to the lan1 interface, where they can be logged. If you log blocked packets this way, you can then analyze blocked traffic for possible attacks on the system. Use block quick for to interface routing because the to interface code will generate two packet paths through IPFilter when used with pass.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||