UDP connections in Statefull Firewalls
UDP connections are simplier to maintain, as they are stateless. When a UDP packet is allowed through the firewall (based on the rulebase) a entry is added to the connections table. Any UDP packet can return within the timeout period (default 40 seconds) as long as both the SRC/DST IP addresses and SRC/DST ports match. For example, below is a DNS query.
Src_IP Src_Prt Dst_IP Dst_Prt IP_prot Kbuf Type Flags Timeout
192.168.1.10 1111 136.1.1.20 53 17 0 16386 ff01ff00 34/40
192.168.1.10 1111 136.1.1.20 0 17 0 16386 ff01ff00 34/40
No comments:
Post a Comment