Methods of screening incoming packets are provided. A first firewall
detects a tunnel formation. A second firewall maintains a list of open
firewall sessions. Each tunnel has one or more associated firewall
sessions. The first firewall detects variable situations, such as when
the tunnel is torn down, and notifies the second firewall so that, for
example, the second firewall can act to clear an associated firewall
session from the firewall session list. Incoming packets that are
associated with firewall sessions that have been cleared from the
firewall session list may not be passed through the second firewall.