Skip to main content

Unit 3 · Topic 3.4

3.4 Protecting Networks: Firewalls

A firewall decides which traffic may enter or leave a network, using an ordered list of rules. This topic covers the three kinds of network firewalls, how to read and write access control list (ACL) rules, why rule order changes the result, and where firewalls belong.

Key terms

  • stateless firewall
  • stateful firewall
  • next-generation firewall (NGFW)
  • access control list (ACL)
  • rule order
  • inbound vs. outbound traffic

Three kinds of firewalls

A firewall is a gatekeeper that decides which traffic may cross into or out of a network. It's software, which can run on a box of its own or inside another device, like a router.

  • A stateless firewall filters each packet on its own, using details in the packet's header: source and destination IP addresses, ports and protocol.
  • A stateful firewall (also called dynamic packet filtering) also keeps track of each connection passing through. It can tell that an incoming packet is a reply to a request a computer inside actually made, and block packets that only pretend to be replies. That gives more control over what gets in and out.
  • A next-generation firewall (NGFW) does everything stateless and stateful firewalls do, plus advanced features: intrusion prevention, deep packet inspection (looking inside the data, not just the header) and filtering by application, such as blocking a file-sharing app no matter which port it uses.

Reading an access control list

Administrators give a firewall an access control list (ACL), a set of rules for permitting or denying traffic. Each rule names the direction (inbound or outbound), what to match (IP address or range, port, service, protocol or application) and the action (allow or deny).

The firewall checks rules from the top, and the first rule that matches decides what happens. Later rules are never checked for that traffic. That's why order matters: a broad deny rule placed above a specific allow rule blocks the traffic the allow rule was meant to let through. Most ACLs end with a deny-everything rule, so anything not explicitly allowed is blocked.

Ports identify services. Ones you'll see often:

PortService
20, 21FTP (file transfer, unencrypted)
22SSH (encrypted remote login)
23Telnet (unencrypted remote login)
25SMTP (email between servers)
53DNS
80HTTP (web, unencrypted)
443HTTPS (web, encrypted)
3389RDP (remote desktop)

Ranges and placement

Rules often name an address range. 203.0.113.0/24 means every address from 203.0.113.0 to 203.0.113.255, because /24 fixes the first three numbers. ALL (or ANY) means every address or port.

Give each network segment its own firewall to control what flows in and out of it, and each segment's firewall can be set to its own security level. Every point where the internal network meets the public internet also needs one.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    The rule-order trap

    A web server's inbound ACL reads: Rule 1: Allow inbound TCP 22 from 198.51.100.0/24. Rule 2: Deny inbound TCP 443 from 203.0.113.0/24. Rule 3: Allow inbound TCP 80 from ALL. Rule 4: Allow inbound TCP 443 from ALL. Rule 5: Deny inbound ALL from ALL. A partner at 203.0.113.40 can't load the HTTPS site. Explain why, and give one change that fixes it without opening HTTPS to every address in that range.

    Show the solution
    1. Step 1: Trace the traffic: inbound TCP to port 443 from 203.0.113.40.
    2. Step 2: Rule 1 is port 22, so no match. Rule 2 is port 443 from 203.0.113.0/24, which includes .40, so it matches, and the traffic is denied. The firewall stops here; Rule 4 is never reached.
    3. Step 3: Swapping Rules 2 and 4 would work, but then Rule 4 (Allow 443 from ALL) would match first for everyone in that range, so Rule 2 would never block anyone, which defeats its purpose.
    4. Step 4: A precise fix: add a new rule above Rule 2: Allow inbound TCP 443 from 203.0.113.40. That one address matches the new rule first, while the rest of the range still hits Rule 2.

    Answer: Rule 2 matches first and denies the partner's HTTPS traffic, so Rule 4 is never checked. Insert "Allow inbound TCP 443 from 203.0.113.40" above Rule 2.

  2. Example 2

    Writing rules from requirements

    Write an ordered inbound ACL for a file server that must: accept SSH only from the IT subnet 198.51.100.0/24; accept HTTPS from anywhere; block everything else.

    Show the solution
    1. Step 1: Start with the most specific allows. SSH uses TCP port 22: Rule 1: Allow inbound TCP 22 from 198.51.100.0/24.
    2. Step 2: HTTPS uses TCP port 443: Rule 2: Allow inbound TCP 443 from ALL.
    3. Step 3: End with the catch-all: Rule 3: Deny inbound ALL from ALL.
    4. Step 4: Check: SSH from 192.0.2.8 skips Rules 1 and 2 and hits Rule 3, so it's denied. SSH from 198.51.100.9 matches Rule 1 and is allowed. HTTPS from anywhere matches Rule 2.

    Answer: 1: Allow inbound TCP 22 from 198.51.100.0/24. 2: Allow inbound TCP 443 from ALL. 3: Deny inbound ALL from ALL.

Common mistakes

  • Reading every rule and picking the "best" one. The firewall stops at the first match, top to bottom.
  • Putting the deny-everything rule first. Then nothing gets through, because it matches all traffic.
  • Fixing an ordering problem in a way that cancels another rule. After any swap, retrace the traffic the old rule was meant to block.
  • Mixing up stateless and stateful. Stateless judges each packet alone; stateful also tracks connections.

On the exam

  • Firewall tables are prime exam material, including the free-response question. Trace the given traffic rule by rule, name the rule number that matches first, and say what changes when rules are reordered or edited.
  • When asked to write or change a rule, include every part: direction, protocol, port, source (or destination) and action, and say where it goes in the order.

Connected topics

Videos

Check yourself: 3.4 Protecting Networks: Firewalls

4 questions on 3.4 Protecting Networks: Firewalls. Pick an answer to see if you got it, and why.

RuleActionDirectionProtocolPortSource
1AllowInboundTCP443ALL
2DenyInboundTCP22ALL
3AllowInboundTCP22198.51.100.0/24
4DenyInboundTCP80203.0.113.0/24
5AllowInboundTCP80ALL
6DenyInboundALLALLALL

Access control list for the firewall in front of an invented company's web server. Port 22 is SSH, port 80 is HTTP and port 443 is HTTPS. 198.51.100.0/24 means 198.51.100.0 through 198.51.100.255; 203.0.113.0/24 means 203.0.113.0 through 203.0.113.255.

Question 1 of 4

An administrator at the branch office, 198.51.100.25, can't connect to the server with SSH. Why?

Question 2 of 4

Which change would let the branch office use SSH while still blocking SSH from everyone else?

Question 3 of 4

A computer at 203.0.113.50 sends two requests to the server: one on TCP port 80 and one on TCP port 443. What happens?

Question 4 of 4

Which traffic would be denied by Rule 6?

0 of 4 answered