How Security Engine process traffic
Security Engines permit or deny traffic according to Engine filtering rules that are contained in an Engine Policy. Rules match based on administrator defined properties of the traffic and the interface.
Each policy is based on a Template Policy. A Template Policy contains necessary predefined rules and also enables automatic rules for the Security Engine to communicate with the SMC. A Engine only passes the traffic that is explicitly allowed in the Engine Policy.
Access rules are traffic handling rules that define how the traffic is examined and what action the Security Engine takes when a rule is matched. You can use the Source, Destination, and Service options to set the matching criteria for the rule. For more information, see the Configuring Access rules topic in the Access rules chapter in the Forcepoint Network Security Platform Product Guide.
Network packets are accepted automatically without additional processing when connection tracking is enabled. When Strict connection tracking mode is used, the Security Engine checks the sequence numbers of the packets in pre-connection establishment states and for RST and FIN packets, and drops packets that are out of sequence. Connections are closed upon completion of the flow (in the case of TCP and FTP) or if there is an inactivity timeout for the session.
Security Engine supports several protocols and their attributes in a Engine policy. The protocols listed in the table are supported. Within each protocol, certain attributes are subject to Engine filtering rules.
| Protocol | Attributes used for matching |
|---|---|
| RFC 792 (ICMPv4) |
|
| RFC 4443 (ICMPv6) |
|
| RFC 791 (IPv4) |
|
| RFC 2460 (IPv6) |
|
| RFC 793 (TCP) |
|
| RFC 768 (UDP) |
|
For more information about the FTP Protocol Agent, see the Define FTP Protocol parameters topic in the Working with Service elements chapter in the Forcepoint Network Security Platform Product Guide.
For more information about dynamic session establishment capabilities, see the Support for multi-layer inspection topic in the Introduction to Forcepoint Network Security Platform in the Engine/VPN role chapter in the Forcepoint Network Security Platform Product Guide.