Apparatus and method for providing a secure gateway for communication and data exchanges between networks
System and method for providing protocol translation and filtering to access the world wide web from wireless or low-bandwidth networks
Network with secure communications sessions
Transparent and secure network gateway
Security system for network address translation systems
Method and system for allowing remote procedure calls through a network firewall
System for securing the flow of and selectively modifying packets in a computer network
Multilevel security port methods, apparatuses, and computer program products
Method and apparatus for dynamic packet filter assignment
System for packet filtering of data packet at a computer network interface
ApplicationNo. 928797 filed on 09/12/1997
ExaminersPrimary: Beausoliel, Robert W. Jr.
Assistant: Elmore, Stephen C.
Foreign Patent References
International ClassH04L 009/00
AbstractComputer network firewalls which include one or more features for increased processing efficiency are provided. A firewall in accordance with the invention can support multiple security policies, multiple users or both, by applying any one of several distinct sets of access rules. The firewall can also be configured to utilize "stateful" packet filtering which involves caching rule processing results for one or more packets, and then utilizing the cached results to bypass rule processing for subsequent similar packets. To facilitate passage to a user, by a firewall, of a separate later transmission which is properly in response to an original transmission, a dependency mask can be set based on session data items such as source host address, destination host address, and type of service. The mask can be used to query a cache of active sessions being processed by the firewall, such that a rule can be selected based on the number of sessions that satisfy the query. Dynamic rules may be used in addition to pre-loaded access rules in order to simplify rule processing. To unburden the firewall of application proxies, the firewall can be enabled to redirect a network session to a separate server for processing.