Previous Topic

Next Topic

Book Contents

Book Index

Packet State and Context Information

To track and act on both state and context information for an application is to treat that traffic statefully. The following are examples of state and context-related information that a firewall should track and analyze:

The ZoneAlarm firewall examines IP addresses, port numbers, and any other information required. It understands the internal structures of the IP protocol family and applications, and is able to extract data from a packet's application content and store it, to provide context in cases where the application does not provide it. The ZoneAlarm firewall also stores and updates the state and context information in dynamic tables, providing cumulative data against which it inspects subsequent communications.

See Also

Check Point Stateful Inspection Technology

The Stateful Inspection Advantage - Passive FTP Example

What Other Stateful Inspection Firewalls Cannot Do