<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic bastille and IPFilter issues in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205323#M733041</link>
    <description>Hi all, &lt;BR /&gt;&lt;BR /&gt;I just added some custom IPFilter rules to a bastilled server, of course I added them in /etc/opt/sec_mgmt/bastille/ipf.customrules.&lt;BR /&gt;&lt;BR /&gt;The I re-applied the bastille config with bastille -b and everything seems OK. &lt;BR /&gt;&lt;BR /&gt;I checked with ipfstat -io and the new rules where there, I also look into ipf.conf and it was OK too but after a reboot of the server when I do an ipfstat -io the new rules aren't there. &lt;BR /&gt;&lt;BR /&gt;Any ideas, am I doing something wrong?&lt;BR /&gt;&lt;BR /&gt;Thx and rgds, &lt;BR /&gt;JMR</description>
    <pubDate>Wed, 21 Oct 2009 13:16:05 GMT</pubDate>
    <dc:creator>jreypo</dc:creator>
    <dc:date>2009-10-21T13:16:05Z</dc:date>
    <item>
      <title>bastille and IPFilter issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205323#M733041</link>
      <description>Hi all, &lt;BR /&gt;&lt;BR /&gt;I just added some custom IPFilter rules to a bastilled server, of course I added them in /etc/opt/sec_mgmt/bastille/ipf.customrules.&lt;BR /&gt;&lt;BR /&gt;The I re-applied the bastille config with bastille -b and everything seems OK. &lt;BR /&gt;&lt;BR /&gt;I checked with ipfstat -io and the new rules where there, I also look into ipf.conf and it was OK too but after a reboot of the server when I do an ipfstat -io the new rules aren't there. &lt;BR /&gt;&lt;BR /&gt;Any ideas, am I doing something wrong?&lt;BR /&gt;&lt;BR /&gt;Thx and rgds, &lt;BR /&gt;JMR</description>
      <pubDate>Wed, 21 Oct 2009 13:16:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205323#M733041</guid>
      <dc:creator>jreypo</dc:creator>
      <dc:date>2009-10-21T13:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: bastille and IPFilter issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205324#M733042</link>
      <description>More info:&lt;BR /&gt;&lt;BR /&gt;If I perform:&lt;BR /&gt;&lt;BR /&gt;mad_svr01 # /sbin/init.d/ipfboot stop&lt;BR /&gt;mad_svr01 # /sbin/init.d/ipfboot start&lt;BR /&gt;&lt;BR /&gt;The new rules are correctly loaded It seems that the problem is only after a reboot of the server.&lt;BR /&gt;&lt;BR /&gt;Rgrds,</description>
      <pubDate>Wed, 21 Oct 2009 13:22:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205324#M733042</guid>
      <dc:creator>jreypo</dc:creator>
      <dc:date>2009-10-21T13:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: bastille and IPFilter issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205325#M733043</link>
      <description>I &lt;THINK&gt; that the reason is the rules are not in the ipf.conf file. When the system is restarting, ipfilter looks at the ipf.conf file for rules, and the custom rules you added were only added to an up and running system, not to the start-up routine. There are better admins than I who could tell you with more confidence. &lt;BR /&gt;&lt;BR /&gt;If your additional rules work, then why not add them to your ipf.conf file. Not only will they be there at reboot, but if your system has lots of ip traffic, you can customize the rule order to make your ipfilter more efficient. For example, you might want to put your "block in quick ..." rules before your "pass out ..." rules so incoming packets can be dropped quicker, instead of progressing down the rule list eating up system resources.&lt;BR /&gt;&lt;BR /&gt;Fred&lt;/THINK&gt;</description>
      <pubDate>Thu, 22 Oct 2009 13:34:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205325#M733043</guid>
      <dc:creator>Fred K. Abell Jr._1</dc:creator>
      <dc:date>2009-10-22T13:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: bastille and IPFilter issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205326#M733044</link>
      <description>Hi Fred. &lt;BR /&gt;&lt;BR /&gt;I agree with you about the ipf.conf, but Bastille manual specifically say to put the new custom rules in the /etc/opt/sec_mgmt/bastille/ipf.customrules file.&lt;BR /&gt;&lt;BR /&gt;Anyway I decided to revert the server to the so-called pre-bastille state and to setup its secuity manually, including IPFilter, password policies, etc.&lt;BR /&gt;&lt;BR /&gt;Thx for your answer.&lt;BR /&gt;&lt;BR /&gt;Rgrds,&lt;BR /&gt;---&lt;BR /&gt;JMR</description>
      <pubDate>Thu, 22 Oct 2009 15:03:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bastille-and-ipfilter-issues/m-p/5205326#M733044</guid>
      <dc:creator>jreypo</dc:creator>
      <dc:date>2009-10-22T15:03:33Z</dc:date>
    </item>
  </channel>
</rss>

