| With the development of modern network, the world has entered the network period. Economic, culture, military and daily life are strongly dependent on computer networks, but the openness of the network provides society and daily life with convenience, at the same time, it also brings many network security issues, the network information security are threatened by many network attacks. To protect network security, the firewall products emerged, rack firewall is a kind of security equipment which is more commonly used in the modern network security.In the project of Prime Rack Firewall, the works the author independently designed and implemented are as follows:1. The packets transmission module. The packets transmission module is the main module in achieving efficiently processing packets. Its main function are that achieving receiving and fast transmitting packets, and filtering packets in using the Netfilter frame in the firewall kernel protocol stack.2. The data interface module. The data interface module is main module in achieving the consistency of user security management, its function are that saving rack map information through adding rack map storage point in system kernel, providing main control board with table operator interface, and achieving rack map information and data table synchronization between main control board and firewall board.3. The hot standby module. The hot standby module is the main module in achieving stable service, its main function are that providing dynamic data synchronization of module with dynamic data synchronization frame, dealing dynamic data synchronization uniformly, and providing with operator interface, so that achieving the management of the user on hot standby module status. In addition, the hot standby module also achieved Session table timing synchronization function in firewall boards.The packets transmission module and data synchronization module implemented the efficiency goals of Prime Rack Firewall, so that the firewall achieve a level of industry-leading. Hot standby module implemented the stability of Prime Rack Firewall, so that the firewall continued to provide security services. |