发明名称 FIREWALL APPARATUS AND METHOD OF CONTROLLING NETWORK DATA PACKET TRAFFIC BETWEEN INTERNAL AND EXTERNAL NETWORKS
摘要 A firewall (3) for controlling network data packet traffic between internal and external networks (1, 5, 4), comprising filtering means selecting from a total set of rules, in dependence of the contents in data fields of a data packet being transmitted between said networks, a rule applicable to the dat a packet, in order to block said packet or forward said packet through the firewall (3). A 2-dimensional address lookup means (8) performs a 2- dimensional lookup of the source and destination addresses of the packet in a set of address prefixes, each prefix having a subset of rules of the total s et of rules, in order to find a prefix, via its representation, associated with said source and destination addresses, and rule matching means (10) for rule matching, on the basis of the contents of said data fields, in order to find the rule applicable to the data packet.
申请公布号 CA2336113(A1) 申请公布日期 2000.01.13
申请号 CA19992336113 申请日期 1999.07.02
申请人 EFFNET GROUP AB 发明人 CARLSSON, SVANTE;LINDHOLM, JOEL;BRODNIK, ANDREJ;JOHANSSON, OLOF;SUNDSTROM, MIKAEL
分类号 G06F13/00;G06F9/46;H04L12/66;H04L29/06;(IPC1-7):G06F17/60;G06F17/30 主分类号 G06F13/00
代理机构 代理人
主权项
地址