
network architecture is built on the seven-layer Open System Interconnection (OSI) model,
where each layer handles specific network protocols.
Figure 16: Network layers and protocols
The firewall in Host Intrusion Prevention provides both stateful packet filtering and stateful
packet inspection.
NOTE: When using IPv6, stateful functionality is only supported on Vista.
Stateful packet filtering
Stateful packet filtering is the stateful tracking of TCP/UDP/ICMP protocol information at Transport
Layer 4 and lower of the OSI network stack. Each packet is examined and if the inspected
packet matches an existing firewall allow rule, the packet is allowed and an entry is made in a
state table. The state table dynamically tracks connections previously matched against a static
rule set, and reflects the current connection state of the TCP/UDP/ICMP protocols. If an inspected
packet matches an existing entry in the state table, the packet is allowed without further scrutiny.
When a connection is closed or times out, its entry is removed from the state table.
Stateful packet inspection
Stateful packet inspection is the process of stateful packet filtering and tracking commands at
Application Layer 7 of the network stack. This combination offers a strong definition of the
Configuring Firewall Policies
Overview of Firewall policies
McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.046
Komentarze do niniejszej Instrukcji