Because passing rules are given precedence over blocking rules (as in standard access control lists common to other filtering systems such as routers or firewalls), one can also create generic blocking rules and more specific passing rules for the purpose of forwarding through the physical layer ports only the packets matching the specific pass rules.