1846683 Members
4049 Online
110256 Solutions
New Discussion

Re: ipf.conf

 
SOLVED
Go to solution
Jason_309
Regular Advisor

ipf.conf

I have never made a new entry in the ipf.conf file. I was wondering if i could get some help. I need to open port 1527 for TNS 9008 for Oracle forms and 8007 for http. Please advice.
4 REPLIES 4
Biswajit Tripathy
Honored Contributor
Solution

Re: ipf.conf

Jason,

Add the following rules to the top of your ipf.conf
file.
----
pass in quick proto tcp from any to any port = 1527 flags S keep state
pass in quick proto tcp from any to any port = 8007 flags S keep state
----

You could replace the "from any" part in both the
above rules if you know exactly which machine or
set of machines or IP address range or network
you are expecting the connections. You could
control the number of connections to these ports
if you want.

Note that, once you add the above rules to ipf.conf
file, you will have to reload the rules.

# /sbin/ipf -Fa -f ipf.conf

- Biswajit
:-)
Robert Bennett_3
Respected Contributor

Re: ipf.conf

Here's a nice how-to

http://www.obfuscation.org/ipf/ipf-howto.html
"All there is to thinking is seeing something noticeable which makes you see something you weren't noticing which makes you see something that isn't even visible." - Norman Maclean
Biswajit Tripathy
Honored Contributor

Re: ipf.conf

Robert Bennette wrote:
> Here's a nice how-to
> http://www.obfuscation.org/ipf/ipf-howto.html

That how-to is for public domain version. While this doc
is perfect for most of the configurations, you should
be looking at the following doc if you are using IPFilter
packaged with HP-UX. HP IPFilter has a major
feature called Dynamic Connection Allocation (DCA)
(section 3 of following doc).

http://www.docs.hp.com/en/B9901-90021/index.html

- Biswajit
:-)