Lab 10

Updated 4 Oct 2026

Lab 10: Basic Linux Firewall

ITS352 & DES352 — Networking Laboratory School of ICT, Sirindhorn International Institute of Technology


Section 1: Firewall Concept

  • A firewall is a device (usually a router or a computer) installed between the internal network of an organization and the rest of the Internet
  • It is designed to forward some packets and filter (not forward) others

Think of a firewall like a security guard at a building entrance — they let authorized people in and stop unauthorized ones from entering.

1.1 Packet-Filter Firewall

  • A firewall can be used as a packet filter
  • It can forward or block packets based on information in the network-layer and transport-layer headers
  • A packet-filter firewall is a router that uses a filter table to decide which packets must be discarded (not forwarded)

1.2 Filter Table Criteria

A filter table lists rules/policies to drop or accept packets according to the following criteria:

  • The source or destination IP address or subnet
  • The source or destination port (transport layer information)
  • The type of protocol (TCP or UDP)
  • The firewall's network interface

Like a bouncer checking a guest list — they look at who you are (IP), where you're going (port), and how you're getting in (protocol).


Section 2: Linux Firewall — Filter Table

2.1 The Three Chains

The filter table in a Linux computer (acting as a firewall) consists of 3 parts called chains. Each chain has firewall rules (policies):

  • INPUT chain — An incoming packet sent to this computer will be checked (accepted or dropped) with the rules in the INPUT chain
  • FORWARD chain — An incoming packet sent to another computer but relayed by this computer will be checked (accepted or dropped) with the rules in the FORWARD chain
  • OUTPUT chain — A packet sent from this computer will be checked (accepted or dropped) with the rules in the OUTPUT chain

Imagine the computer is a post office:

  • INPUT = mail addressed to the post office itself
  • FORWARD = mail passing through the post office to somewhere else
  • OUTPUT = mail sent out by the post office

2.2 Packet Flow Diagram

(Packet flow diagram — INPUT → Local Process → OUTPUT, FORWARD for relayed packets)

2.3 How Rules Are Checked

  • The order of the rules matters
  • In each chain, the packet will be checked rule by rule, from the first rule to the last rule
  • Each chain has a Default Rule (policy) — either ACCEPT or DROP — which is applied if no specific rule matches

Example filter table:

ChainRuleProtocolSourceDestinationAction
INPUT1sticmp192.178.18.0/240.0.0.0/0DROP
INPUT2ndtcp192.178.18.100.0.0.0/0DROP
INPUTDefault———ACCEPT
FORWARD1studp192.178.18.100.0.0.0/0DROP
FORWARD2ndudp0.0.0.0/0192.178.18.10DROP
FORWARDDefault———ACCEPT
OUTPUT1sticmp0.0.0.0/00.0.0.0/0ACCEPT
OUTPUTDefault———DROP

Section 3: Linux Firewall Command — iptables

  • iptables is the Linux command to reset, add, and delete firewall policies/rules in a filter table
  • Requires super-user privilege → must use sudo in front of the command

3.1 Basic iptables Commands

CommandMeaning
sudo iptables -nvLShow the filter table (-n: numeric format, -v: verbose, -L: list all chains)
sudo iptables -FDelete all existing firewall rules
sudo iptables -P <chain> <ACCEPT|DROP>Set the default rule for a chain (INPUT, OUTPUT, or FORWARD)
sudo iptables-save > rule1.txtSave current firewall rules to file rule1.txt
sudo iptables-restore < rule1.txtRestore firewall rules from file rule1.txt

Examples:

  • sudo iptables -P INPUT ACCEPT → by default, all incoming packets are accepted
  • sudo iptables -P OUTPUT DROP → by default, all outgoing packets are dropped
  • sudo iptables -P FORWARD ACCEPT → by default, all relayed packets are accepted

3.2 Adding, Inserting, and Deleting Rules

Syntax:

sudo iptables <action-on-chain> <chain-name> <rule> <action-on-packet>

Action on Chain

FlagMeaning
-AAppend a new rule at the end of a chain
-I <chain> <position>Insert a rule at a specified position (e.g., -I INPUT 3 inserts at position 3); omitting position inserts at the beginning
-DDelete a rule
-PReset the default rule

Chain Names

FlagChain
INPUTINPUT chain
FORWARDFORWARD chain
OUTPUTOUTPUT chain

Rule Options

FlagMeaning
-s <ip-address>Check if packet is from this source IP (e.g., 192.168.18.5)
-s <network-address>Check if packet is from this source network (e.g., 192.168.34.0/24)
-d <ip-address>Check if packet is going to this destination IP
-d <network-address>Check if packet is going to this destination network
-p <protocol>Check protocol type: tcp, udp, icmp, etc.
--sport <port>Check source port (e.g., 21, 53, 80)
--dport <port>Check destination port
-i <NIC>Check if incoming packet enters through this interface (e.g., eth0, eth1)
-o <NIC>Check if outgoing packet exits through this interface

Action on Packet

FlagMeaning
-j ACCEPTAccept this packet if the rule matches
-j DROPDrop this packet if the rule matches

Think of -j as "jump to action" — when a rule matches, jump to either ACCEPT or DROP.


Section 4: Firewall Strategies

There are two general firewall strategies:

4.1 Blacklisting Strategy

  • Default policy: ACCEPT
  • Continuously insert rules to DROP malicious packets
  • "Allow everything except the known bad"

Like allowing all guests into a party EXCEPT those on the banned list.

4.2 Whitelisting Strategy

  • Default policy: DROP
  • Continuously insert rules to ACCEPT good packets
  • "Deny everything except the known good"
  • More secure from a security standpoint — this strategy is more popular/better

Like only allowing guests who are on the approved guest list — everyone else is turned away.

StrategyDefault PolicyInsert Rules to…Security Level
BlacklistingACCEPTDROP bad packetsLower
WhitelistingDROPACCEPT good packetsHigher ✅

Assignment 1: INPUT Chain — Blacklisting Strategy

Goal: Set up firewall rules in the INPUT chain using the blacklisting strategy

RuleDescription
1st RuleDROP all ICMP packets from network 192.168.198.0/24 (change to your network)
2nd RuleDROP TCP packets from IP 35.197.141.103 (SIIT web server)
Default RuleACCEPT all other packets

Check your network with: ifconfig

Step-by-Step: Assignment 1

Step 1.1 — Reset firewall to default

sudo iptables -F INPUT
sudo iptables -P INPUT ACCEPT
sudo iptables -nvL

Step 1.2 — Test network connectivity (before setting rules)

  • Ask a friend to ping your computer → should succeed (reachable)
  • Open www.siit.tu.ac.th in browser → should load completely

Step 1.3 — Set up firewall rules

# Add 1st rule: Drop all ICMP from your subnet
sudo iptables -A INPUT -p icmp -s 192.168.198.0/24 -j DROP
 
# Add 2nd rule: Drop all TCP from SIIT web server
sudo iptables -A INPUT -p tcp -s 35.197.141.103 -j DROP
 
# Verify the filter table
sudo iptables -nvL

Step 1.4 — Test (verify rules work)

  • (a) Ask friend to ping your computer → should FAIL (ICMP blocked) ✅
  • (b) Open www.siit.tu.ac.th in browser → should NOT load (TCP from SIIT blocked) ✅
  • (c) Open www.tu.ac.th in browser → should load successfully (default rule = ACCEPT) ✅

Assignment 2: INPUT Chain — Whitelisting Strategy

Goal: Set up firewall rules in the INPUT chain using the whitelisting strategy

RuleDescription
1st RuleACCEPT all ICMP packets from network 192.168.198.0/24 (change to your network)
Default RuleDROP all other packets

Step-by-Step: Assignment 2

Step 2.1 — Reset firewall to default

sudo iptables -F INPUT
sudo iptables -P INPUT ACCEPT
sudo iptables -nvL

Step 2.2 — Test network connectivity (before setting rules)

  • Open www.tu.ac.th in browser → should load completely

Step 2.3 — Set up firewall rules

# Add 1st rule: Accept ICMP from your subnet
sudo iptables -A INPUT -p icmp -s 192.168.198.0/24 -j ACCEPT
 
# Set default rule to DROP (whitelisting)
sudo iptables -P INPUT DROP
 
# Verify
sudo iptables -nvL

Step 2.4 — Test (verify rules work)

  • (a) Ask friend to ping your computer → should SUCCEED (ICMP accepted by 1st rule) ✅
  • (b) Open www.tu.ac.th in browser → should NOT load (dropped by default DROP rule) ✅

Assignment 3: OUTPUT Chain — Blacklisting Strategy

Goal: Set up firewall rules in the OUTPUT chain using the blacklisting strategy

RuleDescription
1st RuleDROP all outgoing ICMP packets
2nd RuleDROP TCP packets going to www.pantip.com
Default RuleACCEPT all other packets

Note: Using a domain name (www.pantip.com) will automatically resolve to the server's IP addresses and fill them in the filter table.

Step-by-Step: Assignment 3

Step 3.1 — Reset firewall to default (both INPUT and OUTPUT)

sudo iptables -F INPUT
sudo iptables -P INPUT ACCEPT
sudo iptables -F OUTPUT
sudo iptables -P OUTPUT ACCEPT
sudo iptables -nvL

Step 3.2 — Test network connectivity (before setting rules)

  • (a) Ping a friend's computer → should succeed
  • (b) Open www.pantip.com in browser → should load completely

Step 3.3 — Set up firewall rules

# Add 1st rule: Drop all outgoing ICMP
sudo iptables -A OUTPUT -p icmp -j DROP
 
# Add 2nd rule: Drop outgoing TCP to pantip.com
sudo iptables -A OUTPUT -p tcp -d www.pantip.com -j DROP
 
# Verify
sudo iptables -nvL

The system will automatically resolve www.pantip.com to its IP addresses and add multiple DROP rules for each IP.

Step 3.4 — Test (verify rules work)

  • (a) Ping friend's computer → should FAIL (outgoing ICMP blocked) ✅
  • (b) Open www.pantip.com → should NOT load (TCP to pantip blocked) ✅
  • (c) Open www.tu.ac.th → should load successfully (default rule = ACCEPT) ✅

Assignment 4: FORWARD Chain — Whitelisting Strategy (IMUNES, Group of 3)

Goal: Set up firewall rules in the FORWARD chain in Router R1 using the whitelisting strategy

Network Topology (IMUNES)

Computer A              Router R1                  Computer B
eth0: 192.168.5.2/24   eth1: 192.168.5.3/24       eth1: 192.128.10.10/24
                        eth2: 192.128.10.5/24
  • Network A: 192.168.5.0/24
  • Network B: 192.128.10.0/24

FORWARD Chain Rules

RuleDescription
1st RuleACCEPT UDP packets from Network A (192.168.5.0/24)
2nd RuleACCEPT all ICMP packets
Default RuleDROP all other packets

No sudo needed in IMUNES — you are already root.


Step-by-Step: Assignment 4 (IMUNES)

Step 4.1 — Computer A: set default gateway

route add default gw 192.168.5.3

Step 4.2 — Computer B: set default gateway

route add default gw 192.128.10.5

Step 4.3 — Router R1: enable IP forwarding and reset chains

# Enable routing
sysctl -w net.ipv4.ip_forward=1
 
# Reset FORWARD chain to default first
iptables -F FORWARD
iptables -P FORWARD ACCEPT
iptables -nvL

Step 4.4 — Test connectivity (before firewall rules)

# From Computer A:
ping 192.128.10.10    # should succeed
 
# From Computer B:
ping 192.168.5.2      # should succeed

Step 4.5 — Router R1: set up FORWARD chain rules

# Add 1st rule: Accept UDP from Network A
iptables -A FORWARD -p udp -s 192.168.5.0/24 -j ACCEPT
 
# Add 2nd rule: Accept all ICMP
iptables -A FORWARD -p icmp -j ACCEPT
 
# Set default to DROP (whitelisting)
iptables -P FORWARD DROP
 
# Verify — should show 2 rules + DROP default
iptables -nvL

Step 4.6 — Test: Verify ICMP (Rule 2)

# From Computer A:
ping 192.128.10.10    # should SUCCEED ✅
 
# From Computer B:
ping 192.168.5.2      # should SUCCEED ✅

Step 4.7 — Test: Verify UDP A → B (Rule 1)

# On Computer B (UDP server):
nc -luv -p 5000
 
# On Computer A (UDP client):
nc -uvn 192.128.10.10 5000
  • Type Test + Enter at Computer A → message appears at Computer B ✅
  • Type Pass + Enter at Computer B → message does NOT appear at Computer A (B→A UDP is blocked by default DROP) ✅

Step 4.8 — Test: Verify TCP blocked (Default DROP)

# On Computer B (TCP server):
nc -lv -p 5000
 
# On Computer A (TCP client):
nc -vn 192.128.10.10 5000
  • Connection should fail — TCP hits the default DROP rule ✅

Assignment 5: Full Internetwork with Firewall (IMUNES, Group of 4)

Goal: Set up a 2-router internetwork and configure per-machine firewall rules

Network Topology (IMUNES)

Computer A    →    Router R1    →    Router R2    →    Computer B
eth0:              eth0:             eth0:              eth0:
192.168.10.2/24   192.16.10.1/24   192.20.20.3/24    192.40.30.2/24
                   eth1:             eth1:
                   192.20.20.2/24   192.40.30.1/24
MachineInterfaceIP Address
Computer Aeth0192.168.10.2/24
Router R1eth0192.16.10.1/24
Router R1eth1192.20.20.2/24
Router R2eth0192.20.20.3/24
Router R2eth1192.40.30.1/24
Computer Beth0192.40.30.2/24
  • Network A: 192.168.10.0/24 (Computer A side)
  • Network C: 192.20.20.0/24 (between R1 and R2)
  • Network B: 192.40.30.0/24 (Computer B side)

Step 5.1 — Physical Network Diagram

(Draw physical diagram here — label all interfaces and IP addresses)

Firewall Rules Summary

Computer A

ChainRule
INPUTDefault: ACCEPT all
FORWARDDefault: ACCEPT all
OUTPUT1st: DROP ICMP to Network C (192.20.20.0/24); Default: ACCEPT all

Router R1

ChainRule
INPUTDefault: ACCEPT all
FORWARDDefault: ACCEPT all
OUTPUTDefault: ACCEPT all

Router R2

ChainRule
INPUTDefault: ACCEPT all
FORWARDDefault: ACCEPT all
OUTPUT1st: ACCEPT TCP; 2nd: ACCEPT ICMP; Default: DROP all

Computer B

ChainRule
INPUTDefault: ACCEPT all
FORWARDDefault: ACCEPT all
OUTPUTDefault: ACCEPT all

Step-by-Step: Assignment 5 (IMUNES)

Step 5.2 — Computer A: routing + OUTPUT firewall

# Set default gateway to R1
route add default gw 192.16.10.1
 
# Set up OUTPUT chain: drop ICMP to Network C only
iptables -F OUTPUT
iptables -A OUTPUT -p icmp -d 192.20.20.0/24 -j DROP
iptables -P OUTPUT ACCEPT
 
# Verify
iptables -nvL

Step 5.3 — Router R1: enable routing, set all chains to ACCEPT

# Enable IP forwarding
sysctl -w net.ipv4.ip_forward=1
 
# Set default gateway toward R2
route add default gw 192.20.20.3
 
# All chains default ACCEPT (no special rules)
iptables -F INPUT
iptables -F FORWARD
iptables -F OUTPUT
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
 
# Verify
iptables -nvL

Step 5.4 — Router R2: enable routing + OUTPUT whitelisting

# Enable IP forwarding
sysctl -w net.ipv4.ip_forward=1
 
# Set default gateway toward R1
route add default gw 192.20.20.2
 
# Add route back to Network A
route add -net 192.168.10.0/24 gw 192.20.20.2
 
# Set up OUTPUT chain (whitelisting: allow TCP and ICMP only)
iptables -F OUTPUT
iptables -A OUTPUT -p tcp -j ACCEPT
iptables -A OUTPUT -p icmp -j ACCEPT
iptables -P OUTPUT DROP
 
# All other chains default ACCEPT
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
 
# Verify
iptables -nvL

Step 5.5 — Computer B: routing, all chains ACCEPT

# Set default gateway to R2
route add default gw 192.40.30.1
 
# All chains default ACCEPT
iptables -F INPUT
iptables -F FORWARD
iptables -F OUTPUT
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
 
# Verify
iptables -nvL

Step 5.6 — Test network connectivity (before firewall rules)

# From Computer A, ping Computer B:
ping 192.40.30.2    # should succeed
 
# From Computer B, ping Computer A:
ping 192.168.10.2   # should succeed

Step 5.7 — Answer the 5 Questions (Trace Packet Flow)

QScenarioAnswer
aComputer A ping R1 (192.16.10.1)
bComputer A ping Computer B (192.40.30.2)
cComputer B ping R1 Network A IP (192.16.10.1)
dComputer A send UDP to Computer B
eComputer B send TCP to Computer A

Packet trace hints:

(a) Computer A → ping R1 (192.16.10.1)

  • A OUTPUT: ICMP to 192.16.10.1 — not in 192.20.20.0/24 → not blocked
  • Packet reaches R1 directly (same network hop) → R1 replies
  • Answer: Yes ✅

(b) Computer A → ping Computer B (192.40.30.2)

  • A OUTPUT: ICMP to 192.40.30.2 — not in 192.20.20.0/24 → not blocked by A
  • Packet goes to R1 → R1 FORWARD ACCEPT → R2 FORWARD ACCEPT → reaches B
  • B replies → reply passes through R2 (FORWARD chain, not OUTPUT) → R2 FORWARD ACCEPT → R1 FORWARD ACCEPT → reaches A
  • Answer: Yes ✅

(c) Computer B → ping R1 Network A IP (192.16.10.1)

  • B OUTPUT: no rules → R2 FORWARD ACCEPT → R1 FORWARD ACCEPT → reaches R1
  • R1 replies → passes through R2 (FORWARD chain, not OUTPUT) → R2 FORWARD ACCEPT → reaches B
  • Answer: Yes ✅

(d) Computer A → send UDP to Computer B

  • A OUTPUT: UDP not blocked → R1 FORWARD ACCEPT → R2 FORWARD ACCEPT → B receives
  • B replies → reply passes through R2 → hits FORWARD chain (not OUTPUT) → R2 FORWARD ACCEPT → R1 FORWARD ACCEPT → reaches A
  • R2's OUTPUT whitelisting only affects packets originated by R2 itself, not packets being forwarded through it
  • Answer: Yes ✅

(e) Computer B → send TCP to Computer A

  • B OUTPUT: no rules → R2 FORWARD ACCEPT → R1 FORWARD ACCEPT → reaches A
  • A replies → A OUTPUT: TCP not blocked → R1 FORWARD ACCEPT → R2 FORWARD ACCEPT → reaches B
  • Answer: Yes ✅

Quick Reference: Common iptables Commands

# View current filter table (verbose, numeric)
sudo iptables -nvL
 
# Flush (clear) all rules in a specific chain
sudo iptables -F INPUT
sudo iptables -F OUTPUT
sudo iptables -F FORWARD
 
# Set default policy
sudo iptables -P INPUT ACCEPT
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
 
# Append a rule
sudo iptables -A INPUT -p icmp -s 192.168.1.0/24 -j DROP
sudo iptables -A OUTPUT -p tcp -d www.example.com -j DROP
 
# Insert a rule at position 1 (beginning)
sudo iptables -I INPUT 1 -p tcp --dport 80 -j ACCEPT
 
# Delete a rule
sudo iptables -D INPUT 1
 
# Save and restore
sudo iptables-save > backup.txt
sudo iptables-restore < backup.txt

Quiz Preparation

Likely Quiz Topics

Conceptual Questions:

  • What is the difference between blacklisting and whitelisting strategies? Which is more secure?
  • What are the three chains in the Linux filter table? When is each chain used?
  • In what order are firewall rules checked?
  • What happens if no rule matches a packet?
  • What is the difference between -A (append) and -I (insert)?

Command Interpretation Questions: Given a command, identify what it does:

sudo iptables -A INPUT -p tcp -s 10.0.0.0/8 --dport 22 -j DROP

→ Drop all TCP packets from 10.0.0.0/8 network destined for port 22 (SSH) on this computer

Scenario / Trace Questions: Given a filter table, determine if a packet is accepted or dropped:

Remember: rules are checked top to bottom; the first matching rule wins. If no rule matches, the default policy applies.

Short Answer / Explanation:

  • Explain why the whitelisting strategy is more secure than blacklisting
  • Explain the difference between INPUT and FORWARD chains
  • What does sudo iptables -F do? Is it dangerous?
  • If you accidentally DROP yourself out of an SSH session, what happens?

Key Facts to Remember

  • INPUT→packets destined for this machine\boxed{\text{INPUT} \rightarrow \text{packets destined for this machine}}
  • FORWARD→packets passing through (relayed) by this machine\boxed{\text{FORWARD} \rightarrow \text{packets passing through (relayed) by this machine}}
  • OUTPUT→packets originating from this machine\boxed{\text{OUTPUT} \rightarrow \text{packets originating from this machine}}
  • Blacklisting = default ACCEPT, add DROP rules
  • Whitelisting = default DROP, add ACCEPT rules
  • -j ACCEPT = accept the packet; -j DROP = silently discard the packet
  • -s = source; -d = destination; -p = protocol
  • --sport = source port; --dport = destination port
  • -i = incoming interface; -o = outgoing interface
  • Rule order matters — first match wins
  • sudo iptables -P INPUT DROP can lock you out of SSH if you're not careful!