18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 4: Understanding Policy Configuration<br />

IP Filter rule basics<br />

122<br />

How traffic is filtered if stateful packet inspection is<br />

enabled<br />

When <strong>Sidewinder</strong> <strong>G2</strong> receives TCP, UDP, and ICMP traffic, it starts by<br />

checking an IP Filter session record database to determine if an active session<br />

record exists for this traffic. A session record indicates that this traffic is in<br />

response to a previous successful match to an allow rule. Session records only<br />

exist if the matching rule had stateful packet inspection enabled. Stateful<br />

packet inspection is only an option for TCP, UDP, and ICMP IP Filter rules.<br />

If an active session record exists, the following occurs:<br />

a Perform address rewriting, if required<br />

b Perform session processing<br />

c Forward packet directly to the correct destination interface without any<br />

additional processing<br />

If no active session record exists, the following occurs:<br />

<strong>Sidewinder</strong> <strong>G2</strong> uses the criteria in Table 19 to check the active IP Filter rules<br />

and find a match. The description for how the packet proceeds through the<br />

<strong>Sidewinder</strong> <strong>G2</strong> comes after the table. The flowchart in Figure 50 illustrates the<br />

complete process.<br />

Table 19: Rule matching criteria with stateful packet inspection enabled<br />

Protocol Criteria<br />

TCP/UDP • source IP address<br />

• destination IP address<br />

• ports<br />

ICMP • packet type (echo, message, timestamp)<br />

• source IP address<br />

• destination IP address<br />

• If a matching allow rule does exist, the following occurs:<br />

a Add a session record to the session record database.<br />

b Perform Network Address Translation (NAT) if required.<br />

c Session processing occurs.<br />

d Forward packet directly to the correct destination interface without any<br />

additional processing by the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

• If a matching deny rule exists, the packet is discarded without any further<br />

processing.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!