首页> 外国专利> Hardware implementation of complex firewalls using chaining technique

Hardware implementation of complex firewalls using chaining technique

机译:使用链接技术的复杂防火墙的硬件实现

摘要

A firewall device may include a forwarding component that includes a filter block. The filter block may obtain a first hardware-implemented filter, where a hardware implementation limits the first hardware-implemented filter to a maximum quantity of rules; determine whether a last rule associated with the accessed hardware-implemented filter includes a split-filter action, where the split-filter action identifies a second hardware-implemented filter; and link the second hardware-implemented filter to the first hardware-implemented filter to make the second hardware-implemented filter a logical continuation of the first hardware-implemented filter, in response to determining that the last rule includes the split-filter action. The filter block may further determine whether a particular rule of the first hardware-implemented filter includes a next-filter action, where the next filter action identifies a third hardware-implemented filter; and process the third hardware-implemented filter independently of the sequence of hardware attachment points.
机译:防火墙设备可以包括转发组件,该转发组件包括过滤器块。过滤器块可以获得第一硬件实现的过滤器,其中,硬件实现将第一硬件实现的过滤器限制为最大数量的规则;确定与所访问的硬件实现的过滤器相关联的最后规则是否包括拆分过滤器动作,其中拆分过滤器动作标识第二硬件实现的过滤器;响应于确定最后一个规则包括拆分过滤器动作,将第二硬件实现的过滤器链接到第一硬件实现的过滤器,以使第二硬件实现的过滤器成为第一硬件实现的过滤器的逻辑延续。过滤器块可以进一步确定第一硬件实施的过滤器的特定规则是否包括下一过滤器动作,其中下一过滤器动作标识第三硬件实施的过滤器;并独立于硬件连接点的顺序处理第三个由硬件实现的过滤器。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号