04 Try it yourself Interactive

Send a packet at the rule list and watch it stop

The five rules from section 03, and one packet at a time. Each press evaluates one rule: the strip at the top is the packet’s five tuple, the panel under it is the rule being tested with one box per field the rule can constrain, green where the field matches, rose where it does not, and plain grey where the rule left that field as any, and the log records every rule already decided. Evaluation stops on the first match and the narration says why, and names any rule further down that would also have matched and is therefore unreachable. Switch to Stateful firewall and a state table lookup happens before rule 1: the last preset is the reply to a request that already went out, and it is the clearest way to see what state actually buys you. Nothing plays on its own. Next, Back and Reset, or the arrow keys.

Stateless packet filter
no rule evaluated yet
Five values: source IP, source port, destination IP, destination port, protocol. Ports 0 to 65535, protocol TCP or UDP.
Press Next to begin. Each press evaluates one rule.


      
Rules evaluated0
Matching rule
Verdict
State entriesoff
step 0 / 0