White Papers

Real Stateful TCP Packet Filtering in IP Filter

Overview IP Filter is an Open Source packet filtering engine that is available for a number of operating systems, including Solaris and FreeBSD, Open-BSD and NetBSD. IP Filter comes with so-called stateful packet filtering. In the case of TCP, the state engine not only inspects the presence of ACK flags, or looks at source and destination ports, but it includes sequence numbers and window sizes in its decision to pass or block packets. This greatly reduces the window of opportunity for malicious packets to be passed through the packet filter, even in the case when source and destination ports and addresses are known.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Administration and Network Engineering
File Format
PDF
Date Published
Dec 21, 2007
Format
White Papers
Topics
TCP - IP

Similiar White Papers

A Taxonomy of the Linux Network Stack

A Taxonomy of the Linux Network Stack

This paper tries to give readers not familiar with the Linux network stack a gentle introduction to the fundamental conc

Publisher: Oracle  |  Tags: data, ip, kernel, linux, network

Cisco - Access Control Lists and IP Fragments

Cisco - Access Control Lists and IP Fragments

This white paper explains the different kinds of Access Control List (ACL) entries and what happens when different kinds

Publisher: Cisco Systems  |  Tags: ip

Magic Quadrant for Unified Communications, 2007

Magic Quadrant for Unified Communications, 2007

Unified Communications (UC) offer the ability to significantly improve how individuals, groups and companies interact an

Publisher: Gartner  |  Tags: applications, business applications, ip, pbx, uc, unified, unified messaging, voip

How Cisco IT Deploys Closed-Circuit TV Cameras Over the Secure IP Network

How Cisco IT Deploys Closed-Circuit TV Cameras Over the Secure IP Network

Cisco uses video surveillance to help keep its work environment secure. Two years ago, Cisco used a combination of camer

Publisher: Cisco Systems  |  Tags: cctv, data, digital, ip, network, surveillance, tv

VLAN Load Balancing Between Trunks Using the Spanning-Tree Protocol Port Priority

VLAN Load Balancing Between Trunks Using the Spanning-Tree Protocol Port Priority

This paper provides the theory behind VLAN load balancing between trunks, and also provides configuration examples for s

Publisher: Cisco Systems  |  Tags: ip