Concept
Stateful Filtering
Firewalls track connection state so related packets flow without duplicating explicit rules for every phase. OpenStack security groups are stateful by default, simplifying allow lists. Large connection tables consume memory; tune timeouts for long-lived protocols.
1 documentation page cover this concept. Editorial glossary