packet-filtering capability
A network security function — the ability to selectively control the flow of packets to or from an interface by examining information in each packet's header. It is built into most operating systems and routing devices and operates by inspecting packet-level attributes rather than packet content, with its access-control behavior governed by a configured ruleset. In security architecture and compliance contexts, it names the functional property that a device, system, or component is asserted to possess — the built-in or assignable ability to enforce network-layer access controls — and is used when specifying requirements (e.g., that a boundary component *provide* this capability) rather than describing a standalone firewall appliance. Packet-filtering capability is built into most operating systems and into devices capable of routing, such as a network router that employs access control lists.