Figure 15 shows how we can benefit from the tag addition forwarding rules at switch S2:{HTTP, from FW1} -> ProcState = FW; {HTTP, from Proxy1} -> ProcState = Proxy.
The forwarding rules at switch S5 are: {HTTP, ProcState = FW} -> forward to IDS1; and {HTTP, ProcState = Proxy} -> forward to destination. The key concept of this approach is that switch S5 can easily benefit from the ProcState tags to characterize between the first instance of the packet appears in the second segment then forward to IDS and the fourth segment of the packet appears then forward to the
destination.