Security 13-127

Each inspector has a specific task. One inspector’s task may be to examine the destination address of all outgoing packages. That inspector looks for a certain destination—which could be as specific as a street address or as broad as an entire country—and checks each package’s destination address to see if it matches that destination.

INSPECTOR

FROM:

APPROVET : D

FROM:

TO:

FROM:

TO:

A filter inspects data packets like a customs inspector scrutinizing packages.

Filter priority

Continuing the customs inspectors analogy, imagine the inspectors lined up to examine a package. If the package matches the first inspector’s criteria, the package is either rejected or passed on to its destination, depending on the first inspector’s particular orders. In this case, the package is never seen by the remaining inspectors.

packet

first filter

match?

no

send to next filter

yes

pass or

discard?

discard (delete)

pass

to network

Page 127
Image 127
Netopia R910 manual Filter priority