home/glossary/packet-filtering capability

packet-filtering capability

nounverified·updated Aug 30, 2026

A network security function — the ability to selectively control the flow of packets to or from an interface by examining information in each packet's header. It is built into most operating systems and routing devices and operates by inspecting packet-level attributes rather than packet content, with its access-control behavior governed by a configured ruleset. In security architecture and compliance contexts, it names the functional property that a device, system, or component is asserted to possess — the built-in or assignable ability to enforce network-layer access controls — and is used when specifying requirements (e.g., that a boundary component *provide* this capability) rather than describing a standalone firewall appliance. Packet-filtering capability is built into most operating systems and into devices capable of routing, such as a network router that employs access control lists.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Capability95%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
packet-filtering capabilities
possessive
packet-filtering capability's
pluralpossessive
packet-filtering capabilities'