Vigor2800 Series User’s Guide
40
I
I
P
P
F
F
i
i
l
l
t
t
e
e
r
r
s
s
Depending on whether there is an existing Internet connection, or in other words “the WAN
link status is up or down”, the IP filter architecture categorizes traffic into two: Call Filter and
Data Filter.
Call Filter - When there is no existing Internet connection, Call Filter is applied to all
traffic, all of which should be outgoing. It will check packets according to the filter rules.
If legal, the packet will pass. Then the router shall “initiate a call” to build the Internet
connection and send the packet to Internet.
Data Filter - When there is an existing Internet connection, Data Filter is applied to
incoming and outgoing traffic. It will check packets according to the filter rules. If legal,
the packet will pass the router.
The following illustrations are flow charts explaining how router will treat incoming traffic
and outgoing traffic respectively.
S
S
t
t
a
a
t
t
e
e
f
f
u
u
l
l
P
P
a
a
c
c
k
k
e
e
t
t
I
I
n
n
s
s
p
p
e
e
c
c
t
t
i
i
o
o
n
n
(
(
S
S
P
P
I
I
)
)
Stateful inspection is a firewall architecture that works at the network layer. Unlike legacy
static packet filtering, which examines a packet based on the information in its header, stateful
inspection builds up a state machine to track each connection traversing all interfaces of the
firewall and makes sure they are valid. The stateful firewall of Vigor router not just examine
the header information also monitor the state of the connection.
I
I
n
n
s
s
t
t
a
a
n
n
t
t
M
M
e
e
s
s
s
s
e
e
n
n
g
g
e
e
r
r
(
(
I
I
M
M
)
)
a
a
n
n
d
d
P
P
e
e
e
e
r
r
-
-
t
t
o
o
-
-
P
P
e
e
e
e
r
r
(
(
P
P
2
2
P
P
)
)
A
A
p
p
p
p
l
l
i
i
c
c
a
a
t
t
i
i
o
o
n
n
B
B
l
l
o
o
c
c
k
k
i
i
n
n
g
g
Summary of Contents for Vigor2800 Series
Page 2: ...Vigor2800 Series User s Guide ii ...
Page 6: ......
Page 136: ...Vigor2800 Series User s Guide 130 ...
Page 148: ...Vigor2800 Series User s Guide 142 ...
Page 153: ...Vigor2800 Series User s Guide 147 ...
Page 157: ...Vigor2800 Series User s Guide 151 ...