🗺️ Big Picture
Why firewalls? → Perimeter defense for LANs from internet threats
│
├── Firewall Types
│ ├── Packet Filtering (Stateless) — checks headers only, fast, basic
│ ├── Stateful Inspection — remembers connections, smarter
│ ├── Deep Packet Inspection (DPI) — checks payload too
│ ├── Application-Level Gateway — full proxy, per-app auth
│ ├── Circuit-Level Gateway — TCP relay, content-blind
│ ├── Web Application Firewall (WAF) — HTTP/HTTPS app-layer only
│
├── Firewall Basing → Where the firewall lives
│ ├── Bastion Host — hardened platform
│ ├── Host-Based — software on a server
│ └── Personal — software on a PC/router
│
├── Firewall Topologies → Network architecture with firewalls + DMZ
│
├── Evasion Methods → VPN, TOR, Encryption, Proxy, Steganography...
│
└── IPS = IDS + Block Action
├── HIPS — host endpoint
├── NIPS — network inline
├── Snort Inline — open-source IPS
└── UTM — all-in-one appliance
1. Why Firewalls?
- Internet connectivity is essential — but it creates a threat vector
- Firewall = inserted between internal network and the internet → controlled link
- Acts as a perimeter defense — single choke point for security and auditing
🏠 Analogy: A firewall is like the front gate of a building with a security guard checking ID. Nobody enters or exits without going through this single checkpoint.
3 Design Goals (Must Know)
Firewall Capabilities
- Defines a single check point for all traffic
- Monitoring point for security events + auditing
- Platform for IPsec VPN
Firewall Limitations
| Limitation | Why it matters |
|---|---|
| Cannot protect against attacks bypassing it | VPN, TOR, proxy can tunnel right through |
| Internal threats not fully prevented | Insider attacks originate from trusted side |
| Infected mobile devices brought inside | Laptop infected outside → plugged in internally |
| Unsecured wireless LAN | Wi-Fi access points can bypass physical firewall |
🏠 Analogy: Firewall = front door with a guard. If the thief climbs the back fence, or someone inside is the thief, the front guard is useless.
2. Firewall Access Policy
- Lists types of traffic authorized to pass through (addresses, protocols, apps, content)
- Must come from the organization's information security risk assessment
- Start broad → refine to specific filter elements → implement in appropriate topology
Firewall Filter Characteristics
| Filter Type | Description | Used By |
|---|---|---|
| IP address & protocol | Filter on source/dest IP, protocol type | Packet filter, Stateful |
| Application protocol | Monitor specific app protocols (HTTP, FTP) | Application-level gateway |
| User identity | Authenticate internal users | Internal access |
| Network activity | Time of request, rate of requests, patterns | Advanced gateways |
3. Firewall Types — Full Comparison
Quick Overview by Layer
OSI Layer 7 (Application) ← WAF, Application-Level Gateway
OSI Layer 5 (Session) ← Circuit-Level Gateway
OSI Layer 4 (Transport) ← Stateful Inspection (TCP tracking)
OSI Layer 3 (Network) ← Packet Filtering (IP header)
Type 1 — Packet Filtering Firewall (Stateless)
- Applies rules to each packet individually based on IP/TCP header fields
- No memory of previous packets — each packet judged in isolation
Filtering based on:
- Source / Destination IP address
- Source / Destination Port (transport-level)
- IP Protocol field
- Network Interface
Two default policies:
| Policy | Behavior | Security |
|---|---|---|
| Discard (default deny) | Prohibit unless expressly permitted | ✅ More secure, conservative |
| Forward (default allow) | Permit unless expressly prohibited | ❌ Easier to manage but less secure |
Example Packet-Filter Rule Table:
| Rule | Direction | Src Address | Dst Address | Protocol | Dst Port | Action |
|---|---|---|---|---|---|---|
| 1 | In | External | Internal | TCP | 25 | Permit (incoming email) |
| 2 | Out | Internal | External | TCP | >1023 | Permit (return traffic) |
| 3 | Out | Internal | External | TCP | 25 | Permit (outgoing email) |
| 4 | In | External | Internal | TCP | >1023 | Permit (return traffic) |
| 5 | Either | Any | Any | Any | Any | Deny (catch-all) |
🪪 Analogy: Packet filtering = a guard who only checks your ID card (header) against a list. Doesn't care what you're carrying.
Pros: Simple, transparent to users, very fast Weaknesses: Cannot detect app-layer attacks, limited logging, no user auth, vulnerable to IP spoofing, misconfiguration risk
Type 2 — Stateful Inspection Firewall
- Remembers information about previously passed packets (connection state)
- Creates a directory of active TCP connections — only allows return traffic that matches an established session
- Tracks TCP sequence numbers to prevent sequence-based attacks
- Inspects commands in protocols like FTP, IM, SIP
Connection State Table Example:
| Src Address | Src Port | Dst Address | Dst Port | State |
|---|---|---|---|---|
| 192.168.1.100 | 1030 | 210.9.88.29 | 80 | Established |
| 192.168.1.102 | 1031 | 216.32.42.123 | 80 | Established |
| 192.168.1.101 | 1033 | 173.66.32.122 | 25 | Established |
🧠 Analogy: Stateful = a guard who remembers "this person just left to buy coffee, so of course they can come back." Not just checking ID each time — tracking context.
Limitation: Only works at Layers 3–4. Application layer is NOT protected. Cannot authenticate users per connection.
Type 3 — Deep Packet Inspection (DPI)
| Inspection Type | What it checks |
|---|---|
| Stateful Packet Inspection | Header + footer of packet |
| Deep Packet Inspection | The data/payload inside the packet |
DPI sees what's inside the envelope, not just the address on the outside. To bypass DPI → encrypt the payload (e.g., HTTPS, VPN) → DPI can't read it.
Stateless vs. Stateful — Side-by-Side
| Feature | Packet Filtering (Stateless) | Stateful |
|---|---|---|
| Tracks connection state | ❌ No | ✅ Yes |
| Speed | ⚡ Fast (low overhead) | Slightly slower |
| Security level | Basic | Advanced |
| Dynamic port support | ❌ Manual config needed | ✅ Auto-tracks sessions |
| Return traffic handling | ❌ Explicit rules needed | ✅ Auto-allowed if session established |
| Best for | Simple routers, stateless traffic | Enterprise networks, modern apps |
| DoS resistance | ⚠️ Basic | ⚠️ Vulnerable to state exhaustion (too many connections → crash) |
Real-World Examples:
| Task | Stateless | Stateful |
|---|---|---|
| Allow HTTP (port 80) | Allow TCP dst port 80 | Same + auto-allows return responses |
| Block unknown inbound TCP | Must manually block on SYN | Auto-blocks unsolicited SYNs |
| Handle FTP / VoIP (dynamic ports) | Difficult | Easily handled via state tracking |
Type 4 — Application-Level Gateway (Proxy Firewall)
- Acts as a full relay — user connects to gateway, gateway connects to real server
- Must have separate proxy code for each application (HTTP proxy, FTP proxy, etc.)
- User is authenticated at the gateway
- Uses both stateful and deep packet inspection
- Mostly monitors Layer 7 protocols: HTTP, FTP
🧑💼 Analogy: A proxy firewall is a middleman (broker). You can't contact the server directly — you talk to the broker, they verify you, then contact the server for you.
More secure than packet filters, but higher processing overhead per connection.
Type 5 — Circuit-Level Gateway
- Sets up two TCP connections: one to the inner host, one to the outer host
- Relays TCP segments between them without inspecting content
- Security = deciding which connections are allowed
- Used when inside users are trusted
- Lower overhead than application-level gateway
📞 Analogy: A telephone operator who connects your call but doesn't listen to the conversation.
Common pattern: Application-level gateway for inbound, Circuit-level gateway for outbound
Type 6 — Web Application Firewall (WAF)
⚠️ WAF = Web Application ONLY — not a general-purpose network firewall!
- Developed in the early 1990s to address threats beyond traditional firewalls
- Traditional firewalls were bypassed because attacks used authorized protocols (HTTP) to attack apps
- Positioned between web application and client endpoint
- Can be software or hardware
- Is user, session, and application aware
WAF Security Models
| Model | Approach | How |
|---|---|---|
| Positive (Whitelist) | Allow only known-good patterns; reject everything else | "These are the only valid requests" |
| Negative (Blacklist) | Block known-bad patterns; allow everything else | "Block these known attack signatures" |
| Advanced (AI/ML) | Threat intelligence + ML for proactive defense | Learns and adapts |
What WAF Protects Against (App-Layer Attacks)
- SQL Injection, XSS (Cross-Site Scripting)
- Broken Authentication, Broken Access Control
- Sensitive data exposure
- XML External Entities (XXE)
- Security misconfigurations
- Insecure Deserialization
WAF Types
| Type | Description | Trade-offs |
|---|---|---|
| Network-based | Hardware appliance, installed locally | Most expensive; requires physical equipment |
| Host-based | Integrated into app software | Cheaper, customizable; consumes server resources; complex |
| Cloud-based | SaaS subscription | Affordable, easy, auto-updated at no extra cost |
📬 Analogy: Network firewall checks the envelope address. WAF opens and reads the letter inside.
4. Firewall Basing — Where the Firewall Lives
Bastion Host
- Critical, hardened system in the network — serves as the platform for gateways
- Runs a secure OS with only essential services
- Proxy services: small, simple, security-checked, independent, non-privileged
- Limited disk use → read-only code (prevents modification)
- Requires user authentication to access proxy
🏰 Analogy: The strongest fort in the network. Everything is stripped down and hardened — no extras, no weak spots.
Host-Based Firewall
- Software module on a single host (commonly a server)
- Filters and restricts packet flows at the host level
- Rules tailored to the host environment
- Provides protection independent of network topology
- Adds an extra layer on top of network-level firewalls
Personal Firewall
- Controls traffic between a personal computer and the internet
- Typically a software module on the PC, or built into a home router
- Much less complex than enterprise firewalls
- Primary role: deny unauthorized remote access
- Can monitor outgoing traffic to detect worms and malware
5. Firewall Topologies
| Topology | Description |
|---|---|
| Host-resident | Personal firewall software on PCs/servers |
| Screening router | Single router with stateless or stateful packet filtering |
| Single bastion inline | Single firewall between internal router and external router |
| Single bastion T | Bastion has 3rd interface → DMZ for public-facing servers |
| Double bastion inline | DMZ sandwiched between two bastion firewalls |
| Double bastion T | DMZ on a separate interface of the bastion firewall |
| Distributed firewall | Used by large enterprises and government organizations |
📌 Exam note: Know Figure 9.4 — the topology diagrams are exam material!
What is a DMZ (Demilitarized Zone)?
- A network segment between external and internal networks
- Hosts public-facing servers (web server, mail server, DNS)
- Protected by firewall on both sides
- Compromise of DMZ server ≠ compromise of internal network
Internet → [External Firewall] → DMZ (Web/Mail/DNS) → [Internal Firewall] → LAN
6. VPN and Firewalls
- VPN is one of the best ways to bypass firewalls (along with proxy servers)
- When VPN is established, it alters routing tables:
- Outgoing traffic routed into VPN tunnel
- VPN wraps the entire IP datagram inside another TCP packet
- Original packet becomes invisible to the IP layer
- At destination: packet is unwrapped → sent to final destination in original form
7. Firewall Breach Methods
| Method | How it happens |
|---|---|
| Outdated software | Unpatched vulnerabilities in firewall firmware/software |
| Weak passwords | Admin credentials compromised |
| Malware infection | Firewall system itself infected |
| Unsecured remote access | Management ports exposed, brute-forced |
| Incorrectly configured rules | Misconfigured "allow any" rules |
8. Evasion Methods
| Method | How it evades |
|---|---|
| Encrypting data | Firewall/IDS can't inspect ciphertext payload |
| VPN | Tunnels traffic through a trusted endpoint |
| Proxy server | Masks origin of traffic |
| TOR | Anonymizes identity and routes through layered proxies |
| Port hopping | Constantly changes port — static port-block rules fail |
| Steganography | Hides malicious data inside innocent-looking files |
| Application layer protocols | Disguises attacks as valid HTTP/SMTP traffic |
| Malicious code | Malware uses trusted processes to bypass detection |
| Social engineering | Tricks users into bypassing controls themselves |
| Physical access | Direct hardware access bypasses all network controls |
9. TOR (The Onion Router)
- Routes traffic through a three-layer proxy network, encrypting at each hop
- Bounces through volunteer-operated relay servers
- Can access hidden services via
.oniondomain names - Each layer = one level of encryption (like layers of an onion)
🧅 Analogy: Like passing a letter through many middlemen. Each middleman knows only who handed it to them and who to hand it to next — no one knows both the sender and the final recipient.
TOR Node Types
| Node | Role |
|---|---|
| Entry node | First contact — knows your IP, not destination |
| Middle node | Anonymous relay — knows neither origin nor destination |
| Exit node | Last hop before destination — knows destination, not origin |
Why TOR is Hard to Block
| Feature | Why It's Difficult |
|---|---|
| Dynamic exit IPs | Exit nodes change constantly — impossible to blacklist all |
| Encrypted traffic | DPI cannot read the payload |
| Bridges & pluggable transports | Obfuscate TOR to look like normal HTTPS web traffic |
| Non-standard routing | Avoids IP-based geo-blocking or blacklists |
Mitigation strategies: Block known TOR node IPs, behavior/anomaly analysis, advanced traffic fingerprinting
TOR — Good vs. Bad Uses
| ✅ Legitimate | ❌ Malicious |
|---|---|
| Political activists avoiding surveillance | Cybercriminals hiding identity |
| Journalists in authoritarian regimes | Dark web marketplaces (drugs, weapons) |
| Privacy-conscious users | Malware C2, DoS coordination, data exfiltration |
10. IPS — Intrusion Prevention System
- Also called IDPS (Intrusion Detection and Prevention System)
- Extension of IDS — adds ability to block or prevent detected malicious activity
- Can be: host-based, network-based, or distributed/hybrid
- Uses both anomaly detection and signature/heuristic detection
- Can block traffic like a firewall — but uses IDS algorithms to decide when
HIPS — Host-Based IPS
- Installed on the endpoint (desktop, laptop, server)
- Uses signature/heuristic or anomaly detection
Types of malicious behavior HIPS addresses:
| Behavior | Description |
|---|---|
| System resource modification | Unauthorized changes to system files/config |
| Privilege escalation | Guest → Admin level access exploits |
| Buffer overflow exploits | Overflowing memory to gain code execution |
| Email contact list access | Malware harvesting contacts for spam/phishing |
| Directory traversal | Accessing files outside intended directory (e.g., ../../etc/passwd) |
Modern HIPS approach:
- Traditionally: separate products (antivirus, antispyware, personal firewall)
- Now: integrated single-product suite for comprehensive, manageable protection
- Best used as one element in defense-in-depth alongside network-level devices
NIPS — Network-Based IPS
- Inline NIDS with authority to modify or discard packets and tear down TCP connections
- May provide flow data protection — reassembles application payload across multiple packets before analysis
Methods to identify malicious packets:
| Method | How |
|---|---|
| Pattern matching | Each incoming packet matched against known signatures |
| Stateful matching | Scans traffic stream for attack signatures in sequence |
| Protocol anomaly | Checks connections against RFC specifications |
| Traffic anomaly | Detects unusual traffic vs. predefined traffic baseline |
| Statistical anomaly | Compares current traffic stats against normal baseline |
Snort Inline (IPS Mode)
- Turns Snort from an IDS into a full IPS
- Adds a replace option: modify packet contents instead of dropping
- Useful for honeypot implementations — attacker sees failure but can't understand why
| Action | Behavior |
|---|---|
| Drop | Reject packet + log it |
| Reject | Reject + log + send TCP reset (or ICMP unreachable for UDP) |
| Sdrop | Reject — no log (silent, attacker doesn't know) |
🚧 Analogy: Snort IDS = CCTV. Snort Inline = a guard who can physically stop you AND secretly swap the contents of your bag without you knowing.
11. UTM — Unified Threat Management
One appliance → all security functions combined
Inbound traffic processing order:
① Routing module
② VPN module (decrypt inbound VPN)
③ Firewall module
④ Data Analysis Engine
├── Heuristic scan engine
├── Anomaly detection
├── Activity inspection (AV, IDS, IPS)
⑤ Web filtering module
⑥ Antispam module
⑦ VPN module (for outbound VPN)
⑧ Bandwidth shaping module
↓
→ Clean, controlled traffic delivered to internal network
12. Common Port Numbers (Quick Reference)
| Port | Protocol | Usage |
|---|---|---|
| 20 | FTP | Data Transfer |
| 21 | FTP | Command Control |
| 22 | SSH | Secure Shell |
| 23 | Telnet | Remote login (unencrypted ⚠️) |
| 25 | SMTP | Email Routing |
| 53 | DNS | Domain Name Service |
| 80 | HTTP | World Wide Web |
| 110 | POP3 | Email retrieval |
| 119 | NNTP | Network News |
| 123 | NTP | Network Time Protocol |
| 143 | IMAP | Digital mail management |
| 161 | SNMP | Network Management |
| 194 | IRC | Internet Relay Chat |
| 443 | HTTPS | HTTP over TLS/SSL |
🗂️ Summary Table
| Topic | Key Types / Concepts |
|---|---|
| Firewall Types | Packet filter (stateless), Stateful, DPI, Application-level gateway, Circuit-level gateway, WAF |
| Firewall Basing | Bastion host (hardened), Host-based (server software), Personal (PC/router software) |
| Firewall Topologies | Host-resident, Screening router, Single/Double bastion inline/T, Distributed |
| Firewall Locations | DMZ, VPN, Distributed firewalls |
| Evasion Methods | Encryption, VPN, Proxy, TOR, Port hopping, Steganography, Physical access |
| IPS Types | HIPS (endpoint), NIPS (network inline), Snort Inline, Distributed/hybrid |
| UTM | Combines routing, VPN, firewall, AV, IDS/IPS, web filter, antispam, bandwidth shaping |
⚡ Key Facts to Remember
| Fact | Detail |
|---|---|
| Firewall's 3 design goals | All traffic through it; authorized only; immune to penetration |
| Default deny vs. default allow | Deny = more secure; Allow = easier but riskier |
| Stateless vs. Stateful | Stateless = per-packet; Stateful = tracks connections (smarter) |
| Stateful weakness | State exhaustion under DoS → can crash |
| DPI bypass | Encrypt payload → DPI cannot read it |
| Application gateway overhead | Higher overhead — separate proxy code per app |
| Circuit-level gateway | Relays TCP connections; does NOT inspect content |
| WAF only protects | Web applications (HTTP/HTTPS); not general network traffic |
| WAF positive model | Whitelist — allow only known-good |
| WAF negative model | Blacklist — block known-bad |
| Bastion host | Hardened, essential services only, read-only code |
| DMZ purpose | Isolates public servers — compromise ≠ full internal breach |
| VPN vs. firewall | VPN can bypass firewall if FW allows encrypted tunneling |
| IPS = IDS + blocking | IPS acts, IDS only alerts |
| NIPS = inline NIDS | Has authority to drop/modify packets |
| Snort sdrop | Silent drop — attacker doesn't know it was blocked |
| UTM | All-in-one security appliance |
| TOR entry node | Knows your IP; TOR exit node knows destination, not you |
| Port 443 | HTTPS (HTTP over TLS) |
| Port 23 | Telnet — unencrypted, avoid! |