
Packet Filtering and Inspection ◾ 231
the two other remaining packets of the three-way handshake
process are received, the TCP connection state transits to the
ESTABLISHED state. Therefore, the first packet (SYN packet)
of a TCP connection effectively opens a hole in the firewall,
and the cache mechanism allows the return traffic to go
through this hole.
After the TCP connection has been established, the deci-
sion as to whether or not to allow subsequent TCP packets
is based on the contents of the state cache. That is, when a
subsequent TCP packet, with the flag SYN unset and the flag
ACK set, reaches the firewall, the firewall checks whether an