
Appendix D Stateful Packet Filters 725
BCM 4.0 Networking Configuration Guide
Figure 230 Processing of Inbound IP Policy Rules
Stateful session creation
As explained in earlier sections, when the time comes to create a stateful session, the IP header of
the packet is inspected. Based on the protocol type and some protocol specific fields, a decision is
made to create the stateful session. Once a session is created, it is given an initial timeout value so
that it can naturally age out. The session age is refreshed every time a packet is processed for that
existing session. Table 180 summarizes the creation of stateful sessions.
To simplify the explanation, the following acronyms are used:
• PT: IP protocol type
• SA: IP source address
• SP: IP source port (applies to UDP and TCP only)
• DA: IP destination address
• DP: IP destination port (applies to UDP and TCP only)
Commentaires sur ces manuels