×

METHOD AND APPARATUS FOR IMPLEMENTING A LAYER 3/LAYER 7 FIREWALL IN AN L2 DEVICE

  • US 20100281533A1
  • Filed: 07/08/2010
  • Published: 11/04/2010
  • Est. Priority Date: 09/28/2001
  • Status: Active Grant
First Claim
Patent Images

1. An L2 device in a packet switched communication system, the packet switched communication system having plural zones, each zone representing a distinct security domain and having an associated policy for use in inspecting packets entering/exiting an associated zone, the L2 device comprising:

  • at least one port coupled to a terminal unit included in a first security zone;

    at least one port coupled to a terminal unit included in a second security zone;

    a controller determining for each packet received whether the received packet is destined for another zone;

    a firewall engine inspecting and filtering inter-zone packets using a zone specific policy; and

    an L2 switching engine immediately transferring to a port all intra-zone packets passing through the L2 device using a table of MAC addresses and corresponding ports, and only transferring to a port inter-zone packets that are retained after the inspection by the firewall engine.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×