发明名称 Firewall for processing connection-oriented and connectionless datagrams over a connection-oriented network
摘要 The present invention is a device for and method of accessing an information network by initializing a database, an ATM approved list, an IP approved list, and an IP disapproved list; receiving a datagram; discarding the datagram if it is not on the ATM approved list; determining the datagram's type; allowing access to the network and comparing the connection request, if any, to the database if the datagram is ATM signaling; discarding the datagram if the datagram is ATM signaling and the database denies the request; adding the request to the ATM approved list if the datagram is ATM signaling and the database allows the request; allowing access to the network if the datagram is ATM data that excludes IP data and the request is on the ATM approved list; computing a flow tag if the datagram is ATM data that includes IP data; discarding the datagram if the flow tag is on the IP disapproved list; allowing access to the network if the flow tag is on the IP approved list; comparing the flow tag to the database if the flow tag is neither on the IP approved list nor on the IP disapproved list; discarding the datagram and adding the flow tag to the IP disapproved list if the database rejects the flow tag; and allowing access to the network and adding the flow tag to the corresponding approved list if the database accepts the flow tag; and performing these steps on the next datagram
申请公布号 US6615358(B1) 申请公布日期 2003.09.02
申请号 US19990287655 申请日期 1999.04.07
申请人 DOWD PATRICK W.;MCHENRY JOHN T. 发明人 DOWD PATRICK W.;MCHENRY JOHN T.
分类号 H04L12/56;H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L12/56
代理机构 代理人
主权项
地址