Summary of Huawei firewall learning: 2. State detection and conversation mechanism
State detection: configure a rule or policy to match the rule and forward when the message flows from the source area. When the message responds, it is found that the information in the message matches the information in the session, and the message conforms to the provisions of the protocol.
What is the difference between packet filtering and status detection?
① packet filtering firewall only judges whether the message is allowed to pass according to the set static rules. It thinks that the message is stateless and isolated, and does not pay attention to the causes and consequences of the message. This requires that the firewall must configure a rule for messages in each direction, which has low forwarding efficiency and security risks.
② state detection firewall uses a connection state-based detection mechanism to treat all messages belonging to the same connection between two sides of the communication as a whole data flow.