AddStaticFilterFront

Since 3.6.1

Available since: Windows Packet Filter 3.6.1

The AddStaticFilterFront function inserts a static filter rule at the head (index 0) of the driver’s active static filter table at runtime. Because static filter rules are evaluated linearly from first to last, rules placed at the front take precedence over previously configured filters.

Syntax

BOOL WINAPI AddStaticFilterFront(
    _In_ HANDLE         hOpen,
    _In_ PSTATIC_FILTER pFilter
);

Parameters

hOpen
[in] Filter device driver handle returned by a successful call to OpenFilterDriver.

pFilter
[in] Pointer to a STATIC_FILTER structure defining the packet matching criteria and filter action (e.g. FILTER_PACKET_PASS, FILTER_PACKET_DROP, FILTER_PACKET_REDIRECT, FILTER_PACKET_PASS_RDR, FILTER_PACKET_DROP_RDR).

Return Value

If the function succeeds, the return value is TRUE.

If the function fails, the return value is FALSE. Extended error information can be retrieved via GetLastError().

Remarks

This function transmits the IOCTL_NDISRD_ADD_PACKET_FILTER_FRONT control code to ndisrd.sys. Unlike SetPacketFilterTable, which wipes and completely replaces the active filter table, AddStaticFilterFront allows dynamic, atomic runtime prepending of high-priority rules without interrupting existing packet processing.

If the packet filter lookup cache is enabled via EnablePacketFilterCache, modifying the filter list automatically synchronizes cached flow entries in the driver.

See Also

AddStaticFilterBack, InsertStaticFilter, RemoveStaticFilter, STATIC_FILTER, Managing Individual Static Filters