Abstract：Packet filtering of the router is the first defense line for the network security and plays a crucial role. The current studies focus on the data packet detection and filtering, without due consideration of the packet filter device deployment. If the packet filter is deployed properly, the network performance and efficiency can be significantly improved. Packet filters are always placed on the border of the administrative network, the boundaries between trusted and non-trusted networks. Generally, the packet filters are placed on the router in the border of the network, and a tremendous amount of time and space would be consumed, that results in time-delay and congestion, and hampers the efficiency of the network. In this paper, a new disposition algorithm is proposed. To compare various kinds of risks in the border and to remove the edge with operation risks, the packet filters can be placed in an efficient way by generating a shortest border, to provide a perfect protection for trusted networks between the internal network nodes. Experiment results show that the number of packet filters is reduced by 20% to 50%. The network delay time is reduced and the network connectivity is improved.