The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Firewall stateful packet filtering and inspection

Prev Next

Host Intrusion Prevention provides both stateful packet filtering and stateful packet inspection.

Stateful packet filtering is the stateful tracking of TCP/UDP/ICMP protocol information at Transport Layer 4 and lower of the OSI network stack. Each packet is examined. If the inspected packet matches an existing firewall Allow rule, the packet is allowed and an entry is made in a state table. The state table dynamically tracks connections previously matched against a static rule set, and reflects the current connection state of the TCP/UDP/ICMP protocols. If an inspected packet matches an existing entry in the state table, the packet is allowed without further scrutiny. When a connection is closed or times out, its entry is removed from the state table.

Stateful packet inspection is the process of stateful packet filtering and tracking commands at Application Layer 7 of the OSI network stack. This combination offers a strong definition of the computer’s connection state. Access to the application-level commands provides error-free inspection and securing of the FTP protocol.