What happens if IP Filter fails?

"J. Joseph Felten" <[email protected]> Fri, 24 Sep 2010 16:51:39 +0100
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <18883_1285343606_4C9CC976_18883_12440_1_AANLkTikvC76q_5tqmNqi_fuyusF5w4LgJoM-hsGKi-2h@mail.gmail.com>
Sorry if this is obvious to IP Filter veterans.  I searched the FAQ
and Solaris IP Filter documentation and the mailing list etc. etc. and
have not found an answer.

I've created a very simple IP Filter rules set on Solaris 10 to block
access to a particular port from particular IP addresses.  This works
well but what happens if IP Filter fails in some way (perhaps putting
the service in to a maintenance state)?  Isn't the kernel module's
default to pass all?