Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home

HP-UX IPFilter V17 Administrator Guide: HP-UX 11i v2 and HP-UX 11i v3

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Index

HP Part Number: 5900-0395A

Edition: 1

Published: October 2009


Table of Contents

About This Document
Intended Audience
New and Changed Information in This Edition
New Features in this Release
Fixes in this Release
Typographic Conventions
Related Information
Publishing History
HP Encourages Your Comments
1 Overview
Benefits and Features
Supported and Unsupported Features
2 Installing HP-UX IPFilter
Overview of HP-UX IPFilter Installation
Installation and Configuration Checklist
Step 1: Checking HP-UX IPFilter Installation Prerequisites
Step 2: Installing HP-UX IPFilter
Step 3: Verifying the Installation
Step 4: (Optional) Modifying Kernel Tunable Parameters
Removing HP-UX IPFilter
3 Configuring and Loading IPv4 Filter Rules
IPv4 Filter Rules Configuration File
Format
Rule Order and Processing
Basic Rule Syntax: Specifying the Action, Direction, Protocol, IP Addresses, and Ports
pass and block: Specifying the Filter Action
in and out: Specifying the Filter Direction
proto: Specifying the Upper Layer Protocol
from and to: Specifying IP Addresses and Subnets
port: Specifying TCP and UDP Ports
Rate-based Filtering
Processing Options: Logging Packets, Optimizing Rule Processing, and Specifying Interfaces
Option Order
log: Logging Packets
quick: Optimizing IPFilter Rules Processing
on: Filtering by Network Interfaces
Protocol Options: TCP Flags, IP Options and Fragments, ICMP Types and State Information
Option Order
flags: Specifying TCP Header Flags
with opt and ipopts: Specifying IP Options
with frag and with short: Selecting Fragmented IP Packets
icmp-type and code: Filtering ICMP Traffic by Type and Code
keep state: Protecting TCP, UDP, and ICMP Sessions
State Aging
keep frags: Handling IP Fragments
Sending Responses for Blocked TCP and UDP Packets
return-rst: Responding to Blocked TCP Packets
return-icmp-as-dest: Responding to Blocked UDP Packets
Improving Performance with Rule Groups
Loading IPv4 Filter Rules
Verifying IPv4 Filter Rules
Removing IPFilter Rules
Rule Tags
Log Tags
NAT Tags
4 Configuring and Loading IPv6 Filter Rules
IPv6 Filter Rules Configuration File
Features Not Supported with IPv6
IPv6 Filter Rule Syntax Differences
Specifying Addresses
Filtering ICMPv6 Packets
IPv6 Extension Headers
Filtering Tunneled Packets
Filtering IPv6 Fragments
Sending ICMPv6 Responses
Loading IPv6 Filter Rules
Verifying IPv6 Filter Rules
5 Configuring and Loading Dynamic Connection Allocation (DCA) Rules
DCA with HP-UX IPFilter
Overview: DCA Functionality
DCA Rules Configuration Files
DCA Rule Syntax and Keywords
DCA Rule Conditions
keep limit: Limiting Connections
Limiting Connections by IP Address
Limiting Connections by Subnet
Limiting Connections by IP Address Range
Default Individual Connection Limits
return-rst: Returning RESET Packets
cumulative: Limiting Cumulative Connections
log limit: Logging Exceeded Connections
Summary Logs and Cumulative Limits
log limit freq: Log Frequency
Loading and Modifying DCA Rules
Updating keep limit Rules
Adding New keep limit Rules
Integrating keep limit Rules
Extracting an Individual Rule from a Subnet Rule
Enabling and Disabling DCA
Enabling and Disabling DCA Using ipf
Configuring IPFilter to Enable DCA at System Startup Time
Using IPFilter Utilities with DCA
keep limit Rules and Rule Hits
Monitoring and Allocating Memory for DCA Data
6 Configuring and Loading Network Address Translation (NAT) Rules
NAT Rules Configuration File
Format
Rule Order and Processing
NAT Keywords
Rule Examples
map and portmap: Mapping Outbound Packets
Examples
portmap Keyword
map-block: Mapping to a Block of Addresses
rdr: Redirecting Inbound Packets
Redirecting Packets to a Specific Port
Using NAT Redirection with Filtering
Using the rdr and round-robin Keywords for Load Balancing
Sticky NAT Sessions
Checking Connection Health with l4check
bimap: Bidirectional Mapping
Loading NAT Rules
7 Address Pooling
The ippool Utility
The ippool.conf File
Configuring Address Pool
Syntax
Examples
8 Tips for Securing Your System
Blocking Services by Port Number and Protocol
Example: Firewall on a Web Server
Example: Firewall for Multiple Services
Creating a Complete Filter by Interface
Combining IP Address and Network Interface Filtering
Using Bidirectional Filtering
Using HP-UX IPFilter with End System Security Features
9 Troubleshooting HP-UX IPFilter
Viewing IPFilter Statistics and Active Rules with ipfstat
Syntax
Options
Examples
Testing Rules with ipftest
Syntax
Options
Example
Logging IPFilter Packets
Using the log keyword to Configure IPFilter Logging
Using ipmon to View IPFilter Log Entries
Analyzing IPFilter Log Events
Troubleshooting Tips
Reporting Problems
10 HP-UX IPFilter Utilities
The ipf Utility
Syntax
Options
Example
The ipnat Utility
Syntax
Options
Example
The ipfilter Utility (HP-UX 11i v3)
Syntax
Options
Example
The ippool Utility
Syntax
Global Options
Command Options
11 HP-UX IPFilter and ICMP
Filtering ICMPv4 Packets by Type and Code (icmp-type and code)
Configuring ICMPv4 Kernel Parameters
Dead Gateway Detection (ip_ire_gw_probe)
ICMP Source Quench (ip_send_source_quench)
ICMP Redirects (ip_send_redirects)
PMTU Discovery (ip_pmtu_strategy)
ICMP Echo Request Broadcasts (ip_respond_to_echo_broadcast)
Using ndd to Configure ICMPv4 Kernel Parameters
Filtering ICMPv6 Packets by Type and Code (icmpv6–type and code)
Controlling ICMPv6 Router Discovery and Neighbor Discovery Messages
Configuring ipf_icmp6_passthru
12 HP-UX IPFilter and FTP
FTP Basics
WU-FTPD on HP-UX
Running an FTP Server
Active FTP
Passive FTP
Running an FTP Client
Active FTP
Passive FTP
13 HP-UX IPFilter and NFS and RPC
Introduction
Configuring NFS to Use Fixed Ports
Using the rpc.ipfboot Script to Update IPFilter Rules
Rules Files
RPC Rules Configuration File
14 HP-UX IPFilter and IPSec
IPFilter and IPSec Basics
IPSec UDP Negotiation
When Traffic Appears to Be Blocked
Allowing Protocol 50 and Protocol 51 Traffic
IPSec Gateways
15 HP-UX IPFilter and Serviceguard
Using HP-UX IPFilter with Serviceguard
Enabling or Disabling IPFilter
Local Failover
Remote Failover
DCA Remote Failover
A Product Specifications
Configuration Files
Example Configuration Files
Unsupported Features
Supported Utilities
Unsupported Utilities
Supported and Unsupported Interfaces
B HP-UX IPFilter Configuration Examples
BASIC_1.FW
BASIC_2.FW
example.1
example.2
example.3
example.4
example.5
example.6
example.7
example.8
example.9
example.10
example.11
example.12
example.13
example.sr
firewall
server
tcpstate
BASIC.NAT
nat.eg
nat-setup
ipmon.conf
pool.conf
C HP-UX IPFilter Kernel Tunable Parameters
Overview
fr_tcpidletimeout
fr_statemax
ipf_icmp6_passthru
ipl_buffer_sz
Displaying Logging Buffer Statistics
ipl_suppress
ipl_logall
Configuring and Viewing Kernel Tunable Parameters
Configuring Kernel Tunable Parameters on HP-UX 11i v3
Configuring Kernel Tunable Parameters on HP-UX 11i v1 and HP-UX 11i v2
Enabling and Disabling NAT Functionality
D HP-UX IPFilter Static Linking
Overview
Static Linking of HP-UX IPFilter on HP-UX 11i v2 and HP-UX 11i v3
Static Linking of HP-UX IPFilter on HP-UX 11i v1
E Performance Guidelines
System Configuration
Rule Loading
Rule Configuration
Traffic
Performance Monitoring
Index
Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2001-2009 Hewlett-Packard Development Company, L.P.