NF_RULEΒΆ

A rule defines the filtering flag for network activity, described by the other rule fields.

typedef struct _NF_RULE
{
        int             protocol;       // IPPROTO_TCP or IPPROTO_UDP
        unsigned long   processId;      // Process identifier
        unsigned char   direction;      // See NF_DIRECTION (NF_D_IN, NF_D_OUT or NF_D_BOTH)
        unsigned short  localPort;      // Local port
        unsigned short  remotePort;     // Remote port
        unsigned short  ip_family;      // AF_INET for IPv4 and AF_INET6 for IPv6

        // Local IP (or network if localIpAddressMask is not zero)
        unsigned char   localIpAddress[NF_MAX_IP_ADDRESS_LENGTH];

        // Local IP mask
        unsigned char   localIpAddressMask[NF_MAX_IP_ADDRESS_LENGTH];

        // Remote IP (or network if remoteIpAddressMask is not zero)
        unsigned char   remoteIpAddress[NF_MAX_IP_ADDRESS_LENGTH];

        // Remote IP mask
        unsigned char   remoteIpAddressMask[NF_MAX_IP_ADDRESS_LENGTH];

        unsigned long   filteringFlag;  // See NF_FILTERING_FLAG
} NF_RULE, *PNF_RULE;
protocol

Network protocol (IPPROTO_TCP or IPPROTO_UDP). Zero means any protocol.

processId

Process identifier. Zero means any process.

direction

The direction of network activity. Specify NF_D_IN for inbound TCP connections and UDP datagrams, NF_D_OUT for outbound TCP connections and UDP datagrams. Zero or NF_D_BOTH means any direction.

localPort

The local port.

remotePort

The remote port.

ip_family

Describes the family of IP addresses in the rule. Specify AF_INET for IPv4 and AF_INET6 for IPv6. If ip_family is zero, the driver does not use the IP addresses specified in a rule.

localIpAddress

Local IPv4 or IPv6 address. Zero means any address.

localIpAddressMask

If localIpAddressMask is not zero, the rule will be applied to network activity with a local address from the network localIpAddress & localIpAddressMask.

remoteIpAddress

Remote IPv4 or IPv6 address. Zero means any address.

remoteIpAddressMask

If remoteIpAddressMask is not zero, the rule will be applied to network activity with a remote address from the network remoteIpAddress & remoteIpAddressMask.

filteringFlag

A value from NF_FILTERING_FLAG enumeration.

All ports and IP addresses in the rule must be in network byte order. Zero in a rule field means that its value is undefined, and the field will be ignored.

The following values are allowed for filteringFlag:

NF_ALLOW = 0

Allow the activity without filtering transmitted packets. This flag is applied to all network activity that is not matched by any rule.

NF_BLOCK = 1

Block the activity.

NF_FILTER = 2

Filter the transmitted packets, i.e. the packets will be indicated via NF_EventHandler methods.

NF_SUSPENDED = 4

Suspend the indication of new data packets via NF_EventHandler. It is possible to change this flag for a connection or UDP socket using nf_tcpSetConnectionState or nf_udpSetConnectionState.

NF_INDICATE_CONNECT_REQUESTS = 16

The tcpConnectRequest event is called before establishing an outgoing TCP connection. In this event it is possible to modify the filteringFlag and remoteAddress fields in the NF_TCP_CONN_INFO structure. The changes are applied to the connection.