HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.74 Selection of a suitable packet filter

S 2.74 Selection of a suitable packet filter

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrators

Packet filters are routers or computers with special software which use the information in layers three and four of the TCP/IP protocol family (IP, ICMP, ARP, TCP and UDP) for filtering packets. Access and deny lists are used in this regard.

In the event that a packet filter is required for a firewall, the following demands should be made upon purchase:

Dynamic filters

Based on the definition of a packet filter as a filter which uses the information of layers three and four as a check, the limits of this procedure soon become apparent. Although it is possible, in the case of TCP (Transmission Control Protocol) to recognise the establishment of a connection and thereby prohibit connections from the Internet to the network requiring protection, this is no longer possible in the case of UDP (User Datagram Protocol). In order to solve this problem, dynamic packet filters are used. If a UDP packet is sent from an internal computer to a DNS server in the Internet, the dynamic packet filter stores the data (source and destination address, source and destination port) and produces a new permission rule for the response packets. This rule is only valid for a certain period, which can be adjusted. If no response packets are received, it is deleted.


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
July 1999
home