18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 4: Understanding Policy Configuration<br />

IP Filter rule basics<br />

• If a matching bypass rule exists, the packet is forwarded directly to<br />

application-layer processing.<br />

Tip: Bypass rules are used to expedite processing <strong>of</strong> specified traffic by not<br />

checking them against all IP Filters rules before sending them to applicationlevel<br />

processing. Therefore, position bypass IP Filter rules early in the active<br />

rule group.<br />

• If no matching IP Filter rule exists, the packet is forwarded to normal<br />

<strong>Sidewinder</strong> <strong>G2</strong> application-layer processing.<br />

Figure 50: IP Filtering on packets with rules that have stateful packet inspection enabled<br />

TCP/UDP/<br />

ICMP<br />

in<br />

does a<br />

session<br />

exist?<br />

translate as<br />

required<br />

perform<br />

session<br />

processing<br />

forward<br />

message w/o<br />

further<br />

processing<br />

no<br />

match<br />

“bypass”<br />

rule?<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

no<br />

match<br />

“allow”<br />

rule?<br />

yes yes<br />

yes<br />

add a<br />

session<br />

no<br />

match<br />

“deny”<br />

rule?<br />

yes<br />

discard<br />

packet<br />

no<br />

perform<br />

application-layer<br />

processing<br />

out<br />

123

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!