Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home

HP-UX IPFilter Version A.03.05.12 Administrator's Guide: HP-UX 11.0, HP-UX 11i version 1,HP-UX 11i version 2

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Index

HP Part Number: B9901-90029

Edition: September 2005

Published: E0905


Table of Contents

Preface: About This Document
Intended Audience
New and Changed Documentation in This Edition
Publishing History
What is in This Document
Typographical Conventions
HP-UX Release Name and Release Identifier
Related Documents
HP Encourages Your Comments
1 Installing and Configuring HP-UX IPFilter
Overview of HP-UX IPFilter Installation
Installation and Configuration Checklist
Step 1: Checking HP-UX IPFilter Installation Prerequisites
Step 2: Loading HP-UX IPFilter Software
Step 3: Determining the Rules for IPFilter
Step 4: Adding Rules to the Rules Files
Adding IPFilter Rules
Adding NAT Rules
Step 5: Loading IPFilter and NAT Rules
Loading IPFilter Rules
Removing IPFilter Rules
Loading NAT Rules
Step 6: Verifying the Installation and Configuration
Additional Configuration Information
Supported and Unsupported Interfaces
Troubleshooting HP-UX IPFilter
2 Rules and Keywords
IPFilter Configuration Files
IPFilter Rules
IPFilter Configuration File
Basic Rules Processing
IPFilter Keywords
pass and block: Controlling IP Traffic
in and out: Bidirectional Filtering
quick: Optimizing IPFilter Rules Processing
on: Filtering by Network Interfaces
from and to: Filtering by IP Addresses and Subnets
log: Tracking Packets on a System
proto: Controlling Specific Protocols
opt and ipopts: Filtering on IP Options
icmp-type: Filtering ICMP Traffic by Type
port: Filtering on TCP and UDP Ports
keep state: Protecting TCP, UDP, and ICMP Sessions
flags: Tight Filtering Based on TCP Header Flags
keep frags: Letting Fragmented Packets Pass
with frags: Dropping Fragmented Packets
with short: Dropping Short Fragments
return-rst: Responding to Blocked TCP Packets
return-icmp: Responding to Blocked ICMP Packets
dup-to: Drop-Safe Logging
NAT Keywords
map and portmap: Basic NAT
bimap: Bidirectional Mapping
rdr: Redirecting Packets
map-block: Mapping to a Block of Addresses
3 Dynamic Connection Allocation
DCA with HP-UX IPFilter
Overview: DCA Functionality
Using DCA
DCA Keywords
keep limit: Limiting Connections
log limit: Logging Exceeded Connections
log limit freq: Log Frequency
DCA Rule Syntax
DCA Rule Conditions
keep limit Rules and Rule Hits
DCA Rule Modifications
Updating keep limit Rules
Adding New keep limit Rules
Integrating keep limit Rules
Extracting an Individual Rule from a Subnet Rule
DCA Variables
fr_statemax
fr_tcpidletimeout
Configuring Variables
DCA Mode
4 Firewall Building Concepts
Blocking Services by Port Number
Using Keep State
Protecting SSH Server Connections Using Keep State
Using Keep State with UDP
Using Keep State with ICMP
Logging Techniques
level log-level
first
body
Improving Performance with Rule Groups
Localhost Filtering
Using the to Keyword to Capture Blocked Packets
Creating a Complete Filter by Interface
Combining IP Address and Network Interface Filtering
Using Bidirectional Filtering Capabilities
Using port and proto to Create a Secure Filter
5 IPFilter Utilities
The ipf Utility
Syntax
Options
Example
The ipfstat Utility
Syntax
Options
Examples
The ipmon Utility
Syntax
Options
Examples
ipmon and DCA Logging
The ipftest Utility
Syntax
Options
Example
The ipnat Utility
Syntax
Options
Example
Unsupported Utilities and Commands
6 IPFilter and FTP
FTP Basics
WU-FTPD on HP-UX
Running an FTP Server
Active FTP
Passive FTP
Running an FTP Client
Active FTP
Passive FTP
7 IPFilter and RPC
Introduction
Quick Start Information
Configuration Files
Rules Files
RPC Rules Configuration File
8 IPFilter and IPSec
IPFilter and IPSec Basics
IPSec UDP Negotiation
When Traffic Appears to Be Blocked
Allowing Protocol 50 and Protocol 51 Traffic
IPSec Gateways
9 HP-UX IPFilter and MC/ServiceGuard
Using HP-UX IPFilter with MC/ServiceGuard
Local Failover
Remote Failover
DCA Remote Failover
A IPFilter Configuration Examples
BASIC_1.FW
BASIC_2.FW
example.1
example.2
example.3
example.4
example.5
example.6
example.7
example.8
example.9
example.10
example.11
example.12
example.13
example.sr
firewall
server
tcpstate
BASIC.NAT
nat.eg
nat-setup
B IPFilter Static Linking
Static Linking
Static Linking of HP-UX IPFilter on HP-UX 11.0 and HP-UX 11i version 1
Static Linking of HP-UX IPFilter on HP-UX 11i version 2
C Performance Guidelines
System Configuration
Rule Loading
Rule Configuration
Traffic
Performance Monitoring
Index
Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2001-2005 Hewlett-Packard Development Company, L.P.