Defensive filter (-F) primary option

Use the -F primary option to display and manage defensive filters both in the TCP/IP stack and at a global z/OS® system level. Defensive filters deny traffic or simulate a denial. Traffic is checked first against defensive filters. If the traffic is not denied by a defensive filter, then the IP security filters are checked. See defensive filtering information in z/OS Communications Server: IP Configuration Guide for details.

See The z/OS UNIX ipsec command defensive filter (-F) option for parameter descriptions.