How Security Engine process traffic

Security Engines permit or deny traffic according to Engine filtering rules that are contained in an Engine Policy. Rules match based on administrator defined properties of the traffic and the interface.

Each policy is based on a Template Policy. A Template Policy contains necessary predefined rules and also enables automatic rules for the Security Engine to communicate with the SMC. A Engine only passes the traffic that is explicitly allowed in the Engine Policy.

Access rules are traffic handling rules that define how the traffic is examined and what action the Security Engine takes when a rule is matched. You can use the Source, Destination, and Service options to set the matching criteria for the rule. For more information, see the Configuring Access rules topic in the Access rules chapter in the Forcepoint Network Security Platform Product Guide.

Network packets are accepted automatically without additional processing when connection tracking is enabled. When Strict connection tracking mode is used, the Security Engine checks the sequence numbers of the packets in pre-connection establishment states and for RST and FIN packets, and drops packets that are out of sequence. Connections are closed upon completion of the flow (in the case of TCP and FTP) or if there is an inactivity timeout for the session.

Security Engine supports several protocols and their attributes in a Engine policy. The protocols listed in the table are supported. Within each protocol, certain attributes are subject to Engine filtering rules.

Protocol Attributes used for matching
RFC 792 (ICMPv4)
  • Type
  • Code
RFC 4443 (ICMPv6)
  • Type
  • Code
RFC 791 (IPv4)
  • Source address
  • Destination address
  • Transport layer protocol
RFC 2460 (IPv6)
  • Source address
  • Destination address
  • Transport layer protocol
RFC 793 (TCP)
  • Source port
  • Destination port
RFC 768 (UDP)
  • Source port
  • Destination port
Note: With stateful connections, a log entry is created only for the first packet that is seen in the control connection or data connection.
Note: TCP traffic on port 21 is by default interpreted as FTP protocol (RFC 959) traffic. If this control connection is allowed by Access rules and traffic on port 21 contains valid FTP protocol commands to open a data connection, the Security Engine allows those related data connections and logs them using the same settings as configured in Access rules for control connections.

For more information about the FTP Protocol Agent, see the Define FTP Protocol parameters topic in the Working with Service elements chapter in the Forcepoint Network Security Platform Product Guide.

For more information about dynamic session establishment capabilities, see the Support for multi-layer inspection topic in the Introduction to Forcepoint Network Security Platform in the Engine/VPN role chapter in the Forcepoint Network Security Platform Product Guide.