RFC 3514:The Security Flag in the IPv4 Header
RFC-Ref

firewall


Click on the red underlined text to get to the source

... Firewalls [CBR03], packet filters, intrusion detection systems ...


... In networks protected by firewalls, it is axiomatic that all attackers are on the outside of the firewall ...
... firewalls, it is axiomatic that all attackers are on the outside of the firewall. Therefore, hosts inside the firewall ...
... firewall. Therefore, hosts inside the firewall MUST NOT set the evil bit on any packets. ...


... Devices such as firewalls MUST drop all inbound packets that have the evil bit set. Packets with the evil bit ...


... bypass routers (and hence firewalls) entirely. Accordingly, some link-layer scheme MUST be used to denote evil. This may involve evil ...


... bit being set properly. If faulty components do not set the evil bit to 1 when appropriate, firewalls will not be able to do their jobs properly. Similarly, if the bit is set to 1 when it ...


... W.R. Cheswick, S.M. Bellovin, and A.D. Rubin, "Firewalls and Internet Security: Repelling the Wily Hacker", Second Edition, Addison-Wesley, 2003. ...



Google
Web
RFC-Ref