14

Updated 4 Oct 2026


🗺️ Big Picture

Why firewalls? → Perimeter defense for LANs from internet threats
│
├── Firewall Types
│   ├── Packet Filtering (Stateless)    — checks headers only, fast, basic
│   ├── Stateful Inspection             — remembers connections, smarter
│   ├── Deep Packet Inspection (DPI)    — checks payload too
│   ├── Application-Level Gateway       — full proxy, per-app auth
│   ├── Circuit-Level Gateway           — TCP relay, content-blind
│   ├── Web Application Firewall (WAF)  — HTTP/HTTPS app-layer only
│
├── Firewall Basing → Where the firewall lives
│   ├── Bastion Host — hardened platform
│   ├── Host-Based   — software on a server
│   └── Personal     — software on a PC/router
│
├── Firewall Topologies → Network architecture with firewalls + DMZ
│
├── Evasion Methods → VPN, TOR, Encryption, Proxy, Steganography...
│
└── IPS = IDS + Block Action
    ├── HIPS — host endpoint
    ├── NIPS — network inline
    ├── Snort Inline — open-source IPS
    └── UTM  — all-in-one appliance

1. Why Firewalls?

  • Internet connectivity is essential — but it creates a threat vector
  • Firewall = inserted between internal network and the internet → controlled link
  • Acts as a perimeter defense — single choke point for security and auditing

🏠 Analogy: A firewall is like the front gate of a building with a security guard checking ID. Nobody enters or exits without going through this single checkpoint.

3 Design Goals (Must Know)

1. All traffic MUST pass through the firewall\boxed{1.\ \text{All traffic MUST pass through the firewall}} 2. Only AUTHORIZED traffic (per policy) is allowed\boxed{2.\ \text{Only AUTHORIZED traffic (per policy) is allowed}} 3. The firewall itself is immune to penetration\boxed{3.\ \text{The firewall itself is immune to penetration}}

Firewall Capabilities

  • Defines a single check point for all traffic
  • Monitoring point for security events + auditing
  • Platform for IPsec VPN

Firewall Limitations

LimitationWhy it matters
Cannot protect against attacks bypassing itVPN, TOR, proxy can tunnel right through
Internal threats not fully preventedInsider attacks originate from trusted side
Infected mobile devices brought insideLaptop infected outside → plugged in internally
Unsecured wireless LANWi-Fi access points can bypass physical firewall

🏠 Analogy: Firewall = front door with a guard. If the thief climbs the back fence, or someone inside is the thief, the front guard is useless.


2. Firewall Access Policy

  • Lists types of traffic authorized to pass through (addresses, protocols, apps, content)
  • Must come from the organization's information security risk assessment
  • Start broad → refine to specific filter elements → implement in appropriate topology

Firewall Filter Characteristics

Filter TypeDescriptionUsed By
IP address & protocolFilter on source/dest IP, protocol typePacket filter, Stateful
Application protocolMonitor specific app protocols (HTTP, FTP)Application-level gateway
User identityAuthenticate internal usersInternal access
Network activityTime of request, rate of requests, patternsAdvanced gateways

3. Firewall Types — Full Comparison

Quick Overview by Layer

OSI Layer 7 (Application) ← WAF, Application-Level Gateway
OSI Layer 5 (Session)     ← Circuit-Level Gateway
OSI Layer 4 (Transport)   ← Stateful Inspection (TCP tracking)
OSI Layer 3 (Network)     ← Packet Filtering (IP header)

Type 1 — Packet Filtering Firewall (Stateless)

  • Applies rules to each packet individually based on IP/TCP header fields
  • No memory of previous packets — each packet judged in isolation

Filtering based on:

  • Source / Destination IP address
  • Source / Destination Port (transport-level)
  • IP Protocol field
  • Network Interface

Two default policies:

PolicyBehaviorSecurity
Discard (default deny)Prohibit unless expressly permitted✅ More secure, conservative
Forward (default allow)Permit unless expressly prohibited❌ Easier to manage but less secure

Example Packet-Filter Rule Table:

RuleDirectionSrc AddressDst AddressProtocolDst PortAction
1InExternalInternalTCP25Permit (incoming email)
2OutInternalExternalTCP>1023Permit (return traffic)
3OutInternalExternalTCP25Permit (outgoing email)
4InExternalInternalTCP>1023Permit (return traffic)
5EitherAnyAnyAnyAnyDeny (catch-all)

🪪 Analogy: Packet filtering = a guard who only checks your ID card (header) against a list. Doesn't care what you're carrying.

Pros: Simple, transparent to users, very fast Weaknesses: Cannot detect app-layer attacks, limited logging, no user auth, vulnerable to IP spoofing, misconfiguration risk


Type 2 — Stateful Inspection Firewall

  • Remembers information about previously passed packets (connection state)
  • Creates a directory of active TCP connections — only allows return traffic that matches an established session
  • Tracks TCP sequence numbers to prevent sequence-based attacks
  • Inspects commands in protocols like FTP, IM, SIP

Connection State Table Example:

Src AddressSrc PortDst AddressDst PortState
192.168.1.1001030210.9.88.2980Established
192.168.1.1021031216.32.42.12380Established
192.168.1.1011033173.66.32.12225Established

🧠 Analogy: Stateful = a guard who remembers "this person just left to buy coffee, so of course they can come back." Not just checking ID each time — tracking context.

Limitation: Only works at Layers 3–4. Application layer is NOT protected. Cannot authenticate users per connection.


Type 3 — Deep Packet Inspection (DPI)

Inspection TypeWhat it checks
Stateful Packet InspectionHeader + footer of packet
Deep Packet InspectionThe data/payload inside the packet

DPI sees what's inside the envelope, not just the address on the outside. To bypass DPI → encrypt the payload (e.g., HTTPS, VPN) → DPI can't read it.


Stateless vs. Stateful — Side-by-Side

FeaturePacket Filtering (Stateless)Stateful
Tracks connection state❌ No✅ Yes
Speed⚡ Fast (low overhead)Slightly slower
Security levelBasicAdvanced
Dynamic port support❌ Manual config needed✅ Auto-tracks sessions
Return traffic handling❌ Explicit rules needed✅ Auto-allowed if session established
Best forSimple routers, stateless trafficEnterprise networks, modern apps
DoS resistance⚠️ Basic⚠️ Vulnerable to state exhaustion (too many connections → crash)

Real-World Examples:

TaskStatelessStateful
Allow HTTP (port 80)Allow TCP dst port 80Same + auto-allows return responses
Block unknown inbound TCPMust manually block on SYNAuto-blocks unsolicited SYNs
Handle FTP / VoIP (dynamic ports)DifficultEasily handled via state tracking

Type 4 — Application-Level Gateway (Proxy Firewall)

  • Acts as a full relay — user connects to gateway, gateway connects to real server
  • Must have separate proxy code for each application (HTTP proxy, FTP proxy, etc.)
  • User is authenticated at the gateway
  • Uses both stateful and deep packet inspection
  • Mostly monitors Layer 7 protocols: HTTP, FTP

🧑‍💼 Analogy: A proxy firewall is a middleman (broker). You can't contact the server directly — you talk to the broker, they verify you, then contact the server for you.

More secure than packet filters, but higher processing overhead per connection.


Type 5 — Circuit-Level Gateway

  • Sets up two TCP connections: one to the inner host, one to the outer host
  • Relays TCP segments between them without inspecting content
  • Security = deciding which connections are allowed
  • Used when inside users are trusted
  • Lower overhead than application-level gateway

📞 Analogy: A telephone operator who connects your call but doesn't listen to the conversation.

Common pattern: Application-level gateway for inbound, Circuit-level gateway for outbound


Type 6 — Web Application Firewall (WAF)

⚠️ WAF = Web Application ONLY — not a general-purpose network firewall!

  • Developed in the early 1990s to address threats beyond traditional firewalls
  • Traditional firewalls were bypassed because attacks used authorized protocols (HTTP) to attack apps
  • Positioned between web application and client endpoint
  • Can be software or hardware
  • Is user, session, and application aware

WAF Security Models

ModelApproachHow
Positive (Whitelist)Allow only known-good patterns; reject everything else"These are the only valid requests"
Negative (Blacklist)Block known-bad patterns; allow everything else"Block these known attack signatures"
Advanced (AI/ML)Threat intelligence + ML for proactive defenseLearns and adapts

What WAF Protects Against (App-Layer Attacks)

  • SQL Injection, XSS (Cross-Site Scripting)
  • Broken Authentication, Broken Access Control
  • Sensitive data exposure
  • XML External Entities (XXE)
  • Security misconfigurations
  • Insecure Deserialization

WAF Types

TypeDescriptionTrade-offs
Network-basedHardware appliance, installed locallyMost expensive; requires physical equipment
Host-basedIntegrated into app softwareCheaper, customizable; consumes server resources; complex
Cloud-basedSaaS subscriptionAffordable, easy, auto-updated at no extra cost

📬 Analogy: Network firewall checks the envelope address. WAF opens and reads the letter inside.


4. Firewall Basing — Where the Firewall Lives

Bastion Host

  • Critical, hardened system in the network — serves as the platform for gateways
  • Runs a secure OS with only essential services
  • Proxy services: small, simple, security-checked, independent, non-privileged
  • Limited disk use → read-only code (prevents modification)
  • Requires user authentication to access proxy

🏰 Analogy: The strongest fort in the network. Everything is stripped down and hardened — no extras, no weak spots.

Host-Based Firewall

  • Software module on a single host (commonly a server)
  • Filters and restricts packet flows at the host level
  • Rules tailored to the host environment
  • Provides protection independent of network topology
  • Adds an extra layer on top of network-level firewalls

Personal Firewall

  • Controls traffic between a personal computer and the internet
  • Typically a software module on the PC, or built into a home router
  • Much less complex than enterprise firewalls
  • Primary role: deny unauthorized remote access
  • Can monitor outgoing traffic to detect worms and malware

5. Firewall Topologies

TopologyDescription
Host-residentPersonal firewall software on PCs/servers
Screening routerSingle router with stateless or stateful packet filtering
Single bastion inlineSingle firewall between internal router and external router
Single bastion TBastion has 3rd interface → DMZ for public-facing servers
Double bastion inlineDMZ sandwiched between two bastion firewalls
Double bastion TDMZ on a separate interface of the bastion firewall
Distributed firewallUsed by large enterprises and government organizations

📌 Exam note: Know Figure 9.4 — the topology diagrams are exam material!

What is a DMZ (Demilitarized Zone)?

  • A network segment between external and internal networks
  • Hosts public-facing servers (web server, mail server, DNS)
  • Protected by firewall on both sides
  • Compromise of DMZ server ≠ compromise of internal network
Internet → [External Firewall] → DMZ (Web/Mail/DNS) → [Internal Firewall] → LAN

6. VPN and Firewalls

  • VPN is one of the best ways to bypass firewalls (along with proxy servers)
  • When VPN is established, it alters routing tables:
    • Outgoing traffic routed into VPN tunnel
    • VPN wraps the entire IP datagram inside another TCP packet
    • Original packet becomes invisible to the IP layer
  • At destination: packet is unwrapped → sent to final destination in original form

VPN can evade firewall inspection if the firewall permits encrypted tunneling traffic\boxed{\text{VPN can evade firewall inspection if the firewall permits encrypted tunneling traffic}}


7. Firewall Breach Methods

MethodHow it happens
Outdated softwareUnpatched vulnerabilities in firewall firmware/software
Weak passwordsAdmin credentials compromised
Malware infectionFirewall system itself infected
Unsecured remote accessManagement ports exposed, brute-forced
Incorrectly configured rulesMisconfigured "allow any" rules

8. Evasion Methods

MethodHow it evades
Encrypting dataFirewall/IDS can't inspect ciphertext payload
VPNTunnels traffic through a trusted endpoint
Proxy serverMasks origin of traffic
TORAnonymizes identity and routes through layered proxies
Port hoppingConstantly changes port — static port-block rules fail
SteganographyHides malicious data inside innocent-looking files
Application layer protocolsDisguises attacks as valid HTTP/SMTP traffic
Malicious codeMalware uses trusted processes to bypass detection
Social engineeringTricks users into bypassing controls themselves
Physical accessDirect hardware access bypasses all network controls

9. TOR (The Onion Router)

  • Routes traffic through a three-layer proxy network, encrypting at each hop
  • Bounces through volunteer-operated relay servers
  • Can access hidden services via .onion domain names
  • Each layer = one level of encryption (like layers of an onion)

🧅 Analogy: Like passing a letter through many middlemen. Each middleman knows only who handed it to them and who to hand it to next — no one knows both the sender and the final recipient.

TOR Node Types

NodeRole
Entry nodeFirst contact — knows your IP, not destination
Middle nodeAnonymous relay — knows neither origin nor destination
Exit nodeLast hop before destination — knows destination, not origin

Why TOR is Hard to Block

FeatureWhy It's Difficult
Dynamic exit IPsExit nodes change constantly — impossible to blacklist all
Encrypted trafficDPI cannot read the payload
Bridges & pluggable transportsObfuscate TOR to look like normal HTTPS web traffic
Non-standard routingAvoids IP-based geo-blocking or blacklists

Mitigation strategies: Block known TOR node IPs, behavior/anomaly analysis, advanced traffic fingerprinting

TOR — Good vs. Bad Uses

✅ Legitimate❌ Malicious
Political activists avoiding surveillanceCybercriminals hiding identity
Journalists in authoritarian regimesDark web marketplaces (drugs, weapons)
Privacy-conscious usersMalware C2, DoS coordination, data exfiltration

10. IPS — Intrusion Prevention System

IPS=IDS+Prevention (Block) Action\boxed{\text{IPS} = \text{IDS} + \text{Prevention (Block) Action}}

  • Also called IDPS (Intrusion Detection and Prevention System)
  • Extension of IDS — adds ability to block or prevent detected malicious activity
  • Can be: host-based, network-based, or distributed/hybrid
  • Uses both anomaly detection and signature/heuristic detection
  • Can block traffic like a firewall — but uses IDS algorithms to decide when

HIPS — Host-Based IPS

  • Installed on the endpoint (desktop, laptop, server)
  • Uses signature/heuristic or anomaly detection

Types of malicious behavior HIPS addresses:

BehaviorDescription
System resource modificationUnauthorized changes to system files/config
Privilege escalationGuest → Admin level access exploits
Buffer overflow exploitsOverflowing memory to gain code execution
Email contact list accessMalware harvesting contacts for spam/phishing
Directory traversalAccessing files outside intended directory (e.g., ../../etc/passwd)

Modern HIPS approach:

  • Traditionally: separate products (antivirus, antispyware, personal firewall)
  • Now: integrated single-product suite for comprehensive, manageable protection
  • Best used as one element in defense-in-depth alongside network-level devices

NIPS — Network-Based IPS

  • Inline NIDS with authority to modify or discard packets and tear down TCP connections
  • May provide flow data protection — reassembles application payload across multiple packets before analysis

Methods to identify malicious packets:

MethodHow
Pattern matchingEach incoming packet matched against known signatures
Stateful matchingScans traffic stream for attack signatures in sequence
Protocol anomalyChecks connections against RFC specifications
Traffic anomalyDetects unusual traffic vs. predefined traffic baseline
Statistical anomalyCompares current traffic stats against normal baseline

Snort Inline (IPS Mode)

  • Turns Snort from an IDS into a full IPS
  • Adds a replace option: modify packet contents instead of dropping
    • Useful for honeypot implementations — attacker sees failure but can't understand why
ActionBehavior
DropReject packet + log it
RejectReject + log + send TCP reset (or ICMP unreachable for UDP)
SdropReject — no log (silent, attacker doesn't know)

🚧 Analogy: Snort IDS = CCTV. Snort Inline = a guard who can physically stop you AND secretly swap the contents of your bag without you knowing.


11. UTM — Unified Threat Management

One appliance → all security functions combined

Inbound traffic processing order:

① Routing module
② VPN module (decrypt inbound VPN)
③ Firewall module
④ Data Analysis Engine
    ├── Heuristic scan engine
    ├── Anomaly detection
    ├── Activity inspection (AV, IDS, IPS)
⑤ Web filtering module
⑥ Antispam module
⑦ VPN module (for outbound VPN)
⑧ Bandwidth shaping module
    ↓
→ Clean, controlled traffic delivered to internal network

12. Common Port Numbers (Quick Reference)

PortProtocolUsage
20FTPData Transfer
21FTPCommand Control
22SSHSecure Shell
23TelnetRemote login (unencrypted ⚠️)
25SMTPEmail Routing
53DNSDomain Name Service
80HTTPWorld Wide Web
110POP3Email retrieval
119NNTPNetwork News
123NTPNetwork Time Protocol
143IMAPDigital mail management
161SNMPNetwork Management
194IRCInternet Relay Chat
443HTTPSHTTP over TLS/SSL

🗂️ Summary Table

TopicKey Types / Concepts
Firewall TypesPacket filter (stateless), Stateful, DPI, Application-level gateway, Circuit-level gateway, WAF
Firewall BasingBastion host (hardened), Host-based (server software), Personal (PC/router software)
Firewall TopologiesHost-resident, Screening router, Single/Double bastion inline/T, Distributed
Firewall LocationsDMZ, VPN, Distributed firewalls
Evasion MethodsEncryption, VPN, Proxy, TOR, Port hopping, Steganography, Physical access
IPS TypesHIPS (endpoint), NIPS (network inline), Snort Inline, Distributed/hybrid
UTMCombines routing, VPN, firewall, AV, IDS/IPS, web filter, antispam, bandwidth shaping

⚡ Key Facts to Remember

FactDetail
Firewall's 3 design goalsAll traffic through it; authorized only; immune to penetration
Default deny vs. default allowDeny = more secure; Allow = easier but riskier
Stateless vs. StatefulStateless = per-packet; Stateful = tracks connections (smarter)
Stateful weaknessState exhaustion under DoS → can crash
DPI bypassEncrypt payload → DPI cannot read it
Application gateway overheadHigher overhead — separate proxy code per app
Circuit-level gatewayRelays TCP connections; does NOT inspect content
WAF only protectsWeb applications (HTTP/HTTPS); not general network traffic
WAF positive modelWhitelist — allow only known-good
WAF negative modelBlacklist — block known-bad
Bastion hostHardened, essential services only, read-only code
DMZ purposeIsolates public servers — compromise ≠ full internal breach
VPN vs. firewallVPN can bypass firewall if FW allows encrypted tunneling
IPS = IDS + blockingIPS acts, IDS only alerts
NIPS = inline NIDSHas authority to drop/modify packets
Snort sdropSilent drop — attacker doesn't know it was blocked
UTMAll-in-one security appliance
TOR entry nodeKnows your IP; TOR exit node knows destination, not you
Port 443HTTPS (HTTP over TLS)
Port 23Telnet — unencrypted, avoid!