<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ipf -D persistent in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652322#M731365</link>
    <description>I know.&lt;BR /&gt;In fact, as a workaround, we are doing:&lt;BR /&gt;pass out quick on lan901&lt;BR /&gt;pass in quick on lan901&lt;BR /&gt;The matter is: this way, IPFilter does process all packets from lan901, although allowing them to pass.&lt;BR /&gt;However, my understanding is that "ipf -D lan901" does not process packets from lan901.</description>
    <pubDate>Mon, 28 Jun 2010 13:34:07 GMT</pubDate>
    <dc:creator>Jose M. del Rio</dc:creator>
    <dc:date>2010-06-28T13:34:07Z</dc:date>
    <item>
      <title>ipf -D persistent</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652318#M731361</link>
      <description>Hi, &lt;BR /&gt;I'm using IPFilter v. 16 on HP-UX 11.31.&lt;BR /&gt;I would like to disable IPFilter processing for the heartbeat interfaces (Oracle RAC cluster).&lt;BR /&gt;I know "ipf -D interface" does the trick but the change is not persistent (next reboot will clear the exception).&lt;BR /&gt;I was considering adding the command to /sbin/init.d/ipfboot but I would like to know before if there is another way to do it.&lt;BR /&gt;Thanks.&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Jun 2010 06:55:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652318#M731361</guid>
      <dc:creator>Jose M. del Rio</dc:creator>
      <dc:date>2010-06-24T06:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: ipf -D persistent</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652319#M731362</link>
      <description>Jose,&lt;BR /&gt;Maybe I'm not understanding what you want to do. Can you just not start it? Edit the /etc/rc.config.d/ipfconf file and make IPF_START=0 instead of =1.</description>
      <pubDate>Thu, 24 Jun 2010 17:59:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652319#M731362</guid>
      <dc:creator>Fred K. Abell Jr._1</dc:creator>
      <dc:date>2010-06-24T17:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: ipf -D persistent</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652320#M731363</link>
      <description>The servers have two interfaces:&lt;BR /&gt;- lan900 to the corporate network&lt;BR /&gt;- lan901 tp the heartbeat network.&lt;BR /&gt;I want IPfilter to monitor lan900 but to exempt lan901.</description>
      <pubDate>Sat, 26 Jun 2010 06:00:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652320#M731363</guid>
      <dc:creator>Jose M. del Rio</dc:creator>
      <dc:date>2010-06-26T06:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: ipf -D persistent</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652321#M731364</link>
      <description>In your ipf.conf file, make the rules lan specific. For example:&lt;BR /&gt;&lt;BR /&gt;block in quick on lan0 proto udp from any to any port = netbios_ns&lt;BR /&gt;&lt;BR /&gt;This "block in" command for udp packets will only be applied to lan0. If all your rules are set to work on lan901, then lan900 will be ignored. If you had the following:&lt;BR /&gt;&lt;BR /&gt;block in quick proto udp from any to any port = netbios_ns&lt;BR /&gt;&lt;BR /&gt;then all lans would be filtered.&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Mon, 28 Jun 2010 13:25:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652321#M731364</guid>
      <dc:creator>Fred K. Abell Jr._1</dc:creator>
      <dc:date>2010-06-28T13:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: ipf -D persistent</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652322#M731365</link>
      <description>I know.&lt;BR /&gt;In fact, as a workaround, we are doing:&lt;BR /&gt;pass out quick on lan901&lt;BR /&gt;pass in quick on lan901&lt;BR /&gt;The matter is: this way, IPFilter does process all packets from lan901, although allowing them to pass.&lt;BR /&gt;However, my understanding is that "ipf -D lan901" does not process packets from lan901.</description>
      <pubDate>Mon, 28 Jun 2010 13:34:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipf-d-persistent/m-p/4652322#M731365</guid>
      <dc:creator>Jose M. del Rio</dc:creator>
      <dc:date>2010-06-28T13:34:07Z</dc:date>
    </item>
  </channel>
</rss>

