Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Windows Filtering Platform

From Wikipedia, the free encyclopedia
This article includes alist of references,related reading, orexternal links,but its sources remain unclear because it lacksinline citations. Please helpimprove this article byintroducing more precise citations.(March 2025) (Learn how and when to remove this message)
Network services in Microsoft Windows

Windows Filtering Platform (WFP) is a set ofsystem services inWindows Vista and later that allows Windows software to process and filter network traffic. Microsoft intended WFP for use byfirewalls,antimalware software, andparental controls apps. Additionally, WFP is used to implement NAT and to store IPSec policy configuration.

WFP relies on Windows Vista'sNext Generation TCP/IP stack. It provides features such as integrated communication and per-application processing logic. Since Windows 8 and Windows Server 2012, WFP allows filtering at the second layer ofTCP/IP suite.

Components

[edit]

The filtering platform includes the following components:

  • Filtering engine, which spans bothkernel-mode anduser-mode, providing basic filtering capabilities. It matches the data within a packet – as exposed by the shims – against filtering rules, and either blocks or permits the packet. Acallout (see below) may implement any other action as required. The filters operate on a per-application basis. To mitigate conflicts between filters, they are givenweights (priorities) and grouped intosublayers, which also have weights. Filters and callouts may be associated toproviders which may be given a name and description and are essentially associated to a particular application or service.
  • Base filtering engine, the module that manages the filtering engine. It accepts filtering rules and enforces the security model of the application. It also maintains statistics for the WFP and logs its state.
  • Callout, acallback function exposed by a filtering driver. The filtering drivers provide filtering capabilities other than the default block/allow. Administrators specify a callout function during registration of a filter rule. When the filter matches, the system invokes the callout, which handles a specified action.

Diagnostics

[edit]

Starting withWindows 7, thenetsh command can diagnose of the internal state of WFP.

Hotfix

[edit]

Microsoft released three out-of-band hotfixes for WFP in Windows Vista and Windows 7 to address issues that could cause a memory leak, loss of connectivity during aRemote Desktop Connection session, or ablue screen of death. Later, these hotfixes were rolled up into one package.[1]

References

[edit]
  1. ^"A Windows Filtering Platform (WFP) driver hotfix rollup package is available for Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2".Windows support. Microsoft. 12 April 2010.

External links

[edit]
Graphics and UI
Audio
Multimedia
Web
Data access
Networking
Communication
Administration and
management
Component model
Libraries
Device drivers
Security
.NET
Software factories
IPC
Accessibility
Text and multilingual
support
Retrieved from "https://en.wikipedia.org/w/index.php?title=Windows_Filtering_Platform&oldid=1294276387"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp