Method and apparatus for a distributed firewall
A method and apparatus for implementing a distributed firewall is described. A packet filter processor receives a packet sent from a first device to a second device. The packet filter processor authenticates an identifier for the packet. For example, authentication could be performed using a cryptographically-verifiable identifier. The packet filter processor determines whether to send the packet to the second device, based on the authentication and a set of policy rules. The packet filter processor sends the packet to the second device in accordance with the determination
1 - 2 . (canceled)
3 . A method for filtering packets, comprising:
receiving a packet sent from a first device to a second device;
authenticating an identifier for said packet;
determining whether to send said packet to said second device; and
sending said packet to said second device in accordance with said determination wherein said identifier is a common host identifier.
4 - 22 . (canceled)
23 . A method for filtering packets, comprising:
receiving a packet sent from a first device to a second device;
authenticating an identifier for said packet;
determining whether to send said packet to said second device; and
sending said packet to said second device in accordance with said determination
further comprising a second buffer for storing said compared data packet prior to forwarding said compared data packet to the second device
wherein said random access memory comprises dynamic random access memory.
24 . The apparatus of claim 23 , further comprising a non-volatile random access memory for storing parameters used by said operating system program
25 . The apparatus of claim 24 , further comprising means for receiving an updated list of origination addresses.
26 . The apparatus of claim 25 , wherein said means for receiving comprises an asynchronous terminal device and a serial port coupled to said dynamic random access memory.
27 . The apparatus of claim 25 , wherein said means for receiving comprises a network interface card coupled to said dynamic random access memory
28 . The apparatus of claim 21 , wherein said first network is a wireless network, and said input means comprises means for receiving said data packets from said wireless network.
29 . A distributed firewall system, comprising:
a first network device;
a second network device in communication with said first network device;
a packet filter processor for each network device;
an encryption means coupled to said packet filter processor, said encryption means for decrypting and authenticating a packet sent between said first network device and said second network device; and
a system management module to manage said packet filter processors.
30 . The system of claim 29 wherein said authenticating comprises:
retrieving a pointer to a security association from an authentication header from said packet;
retrieving a key associated with said security association; and
determining whether said packet is authentic using said key.
31 . (Previously added): The system of claim 30 wherein said authentication header is an IPSEC authentication header.