EnablePacketFilterCache

Since 3.6.1

Available since: Windows Packet Filter 3.6.1

The EnablePacketFilterCache function activates the kernel driver’s flow-level static filter lookup cache. When enabled, ndisrd.sys caches filter match decisions for recurring network flows, bypassing linear table scans for subsequent packets belonging to known flows.

Syntax

BOOL WINAPI EnablePacketFilterCache(
    _In_ HANDLE hOpen
);

Parameters

hOpen
[in] Filter device driver handle returned by OpenFilterDriver.

Return Value

Returns TRUE if the cache was successfully activated; otherwise returns FALSE.

Remarks

This function transmits IOCTL_NDISRD_SET_FILTER_CACHE_STATE with a state flag of TRUE. Enabling the filter cache is highly recommended in environments with complex rule sets (dozens or hundreds of static filters) experiencing high packet volume, as flow caching reduces per-packet CPU overhead significantly.

See Also

DisablePacketFilterCache, EnablePacketFragmentCache, Managing Individual Static Filters