发明名称 Firewall with stateful inspection
摘要 A network security device for controlling the flow of packets into and out of an internal network , includes first and second network cards and a stateful inspection firewall. The first network card forwards each packet for inspection to determine whether or not the packet is part of an existing session. If the packet is part of an existing session it will be forwarded to the second network card and on to the internal network. If the packet is not part of an existing session it will be compared with a set of rules to determine whether the packet is acceptable or not acceptable to the network. If the packet is acceptable, it will be forwarded to the second network card and to the internal network and the session is entered into the stateful inspection table, and if the packet is not acceptable it will be dropped and will disappear. During the outflow of packets an outbound packet passes through the second network card where it is inspected to determine whether or not it is part of an existing session and, if so, it is forwarded to the first network card to exit the device, and, if not, it is compared with the set of rules and if the packet is acceptable it is forwarded to the first network card to exit the device and, if not, it is dropped and disappears.
申请公布号 US7512781(B2) 申请公布日期 2009.03.31
申请号 US20050512950 申请日期 2005.06.13
申请人 FIREBRIDGE SYSTEMS PTY LTD. 发明人 CULBERT PATRICK
分类号 G06F13/00;H04L9/00;H04L12/66;H04L29/06 主分类号 G06F13/00
代理机构 代理人
主权项
地址