| United States-English |
|
|
|
![]() |
HP-UX IPFilter Version A.03.05.12 Administrator's Guide: HP-UX 11.0, HP-UX 11i version 1,HP-UX 11i version 2 > Chapter 4 Firewall
Building Concepts Creating a Complete Filter by Interface |
|
When you create a ruleset, you should set up rules for all directions and all interfaces. The default state of IPFilter is to pass packets both in and out. Instead of relying on the IPFilter default behavior, make every ruleset as specific as possible, interface by interface, until all possibilities are explicitly covered. For example, if you have an IPFilter system with a lan1 interface, and a lan0 interface, configure the following rules:
In this example, no restrictions are on traffic in and out on lan1. Traffic has significant restrictions both in and out of lan0.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||