×

Method and apparatus for implementing a layer 3/layer 7 firewall in an L2 device

DC
  • US 7,302,700 B2
  • Filed: 09/28/2001
  • Issued: 11/27/2007
  • Est. Priority Date: 09/28/2001
  • Status: Active Grant
First Claim
Patent Images

1. An L2 device comprising:

  • at least one port to couple to a terminal unit included in a first security zone;

    at least one port to couple to a terminal unit included in a second security zone that is distinct from the first security zone;

    a controller to determine for each packet received from either the first security zone or the second security zone whether the received packet is an inter-zone packet destined for the other of the first security zone or the second security zone;

    a firewall engine to inspect and filter received inter-zone packets using a zone specific policy; and

    an L2 switching engine to transfer to a port associated with intra-zone transfer, without inspection by the firewall engine, received intra-zone packets using a table of MAC addresses and corresponding ports, and to transfer to a port associated with inter-zone transfer, inter-zone packets that are retained after the inspection by the firewall engine.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×