EMZETT.
Login

Firewall

Firewall Image: Unbekannt, CC BY-SA 3.0 de, Wikimedia Commons

In short: A system (hardware or software) that filters network traffic between two networks based on predefined rules and blocks unwanted connections.

In more detail: A firewall typically sits between an internal, trusted network (e.g. a company network) and an external, untrusted network (internet). Rules usually work on the basis of IP addresses, ports and protocols — e.g. “only allow incoming traffic on port 22 from certain IPs”. A distinction is made between packet filters (check individual packets), stateful firewalls (track the state of whole connections) and application-layer firewalls (check content at the application level).

In Depth

A typical firewall rule list (simplified here in the style of iptables/cloud security groups) follows the principle “only allow what’s explicitly named, block the rest”:

ALLOW  incoming  TCP  port 443 (HTTPS)  from anywhere
ALLOW  incoming  TCP  port 22  (SSH)    only from the office IP range
ALLOW  outgoing  all ports               (the server may make requests itself)
BLOCK  incoming  everything else         (default rule at the end)

The order of the rules is crucial: most firewalls evaluate rules from top to bottom and apply the FIRST one that matches — a rule that’s too broad further up can completely override a more specific, more restrictive rule below it.

A distinction is also made by location in the infrastructure: a network firewall sits at the edge of an entire network (e.g. at a company’s internet access) and protects all devices behind it together. A host-based firewall (e.g. ufw/Windows Defender Firewall) runs directly on a single device and only filters that device’s own traffic — in practice both levels are often combined (“defence in depth”: several independent layers of protection, so that one breached layer doesn’t immediately compromise the whole system).

Web application firewalls (WAFs) are a more specialised variant that works at the application layer: instead of only checking IP/port, they analyse the content of HTTP requests and can, for example, detect and block typical SQL injection patterns before they reach the actual application.

Stateful vs. stateless filtering

The difference between a simple packet filter and a stateful firewall is practically significant: a pure packet filter looks at each packet in isolation and therefore has to define separate rules for outgoing requests AND the corresponding incoming responses — error-prone and confusing. A stateful firewall, on the other hand, remembers the state of existing connections (which internal computer made a request to which external server and when) and automatically allows the corresponding response without an explicit rule being needed for it — this is the standard approach in practically every modern firewall today.

Next-generation firewalls

Modern “next-generation firewalls” (NGFW) go beyond classic packet/connection filtering: they combine firewall functionality with intrusion detection/prevention systems (recognising known attack patterns in the traffic itself), deep packet inspection (checking the actual content of packets, not just header information) and sometimes even application recognition (distinguishing, say, “normal HTTPS traffic” from “disguised tunnelling traffic over port 443”). This range of functions makes them much more powerful, but also more complex to configure than classic packet filters.

Firewall rules as a common source of errors

A surprisingly common cause of real security incidents isn’t sophisticated attack techniques but simply misconfigured firewall rules — for example a cloud database accidentally opened for “0.0.0.0/0” (i.e. the whole internet) instead of only for your own application server’s IP. Such misconfigurations are one of the main causes of the mass data leaks from cloud-hosted databases that regularly appear in the news — automated scanning tools (similar to Nmap) continuously search the internet for such openly reachable services that were actually meant to be private.

Firewalls in combination with other protective measures

A firewall alone doesn’t protect against attacks that run over permitted ports/protocols (e.g. an attack via legitimate HTTPS traffic on port 443) — it’s one of several layers of defence, not the only one. Only in combination with VPN access for remote employees, intrusion detection systems and regular security updates does a more comprehensive protection concept (“defence in depth”) emerge.

See also: Security, VPN