BIT451 Network and System Administration

Network and System AdministrationUnit 511 min read

Network Security & Firewalls: Types, Rules, Real-World Use

Unit 5 of Network and System Administration explores firewalls (packet-level vs. application-level), security threats, access control lists (ACLs), intrusion detection systems (IDS), and VPNs—with real-world examples from Nepali banks, eSewa, and global tech giants like Google. Learn how firewalls filter traffic, how A

TAKEAWAYS:

  • Firewalls act as gatekeepers between trusted internal networks and untrusted external ones, filtering traffic based on rules (ACLs) to block malicious activity.
  • Packet-level firewalls inspect headers (source/destination IP, ports) while application-level firewalls analyze payloads (e.g., SQL queries, HTTP content).
  • Security threats like DDoS, phishing, and man-in-the-middle attacks exploit vulnerabilities; firewalls, IDS/IPS, and VPNs mitigate these risks.
  • Access Control Lists (ACLs) define granular permissions (e.g., allow HTTP/HTTPS, block ICMP) to enforce security policies.
  • VPNs encrypt traffic over public networks (e.g., Pathao drivers using mobile data) to ensure confidentiality and integrity.
  • Real-world tie-ins: Nepali banks use firewalls to block fraudulent transactions, eSewa encrypts payments via VPNs, and Google’s Gmail filters spam with application-level firewalls.

1. Why Network Security Matters

Networks are target-rich environments for attackers. Without security measures, threats like:

  • Unauthorized access (e.g., hackers exploiting weak passwords).
  • Data breaches (e.g., customer records stolen from Daraz’s database).
  • Denial-of-Service (DoS/DDoS) (e.g., overwhelming NTC’s servers to disrupt internet).
  • Malware (e.g., ransomware locking NEPSE’s trading systems).

Solution: Defense in depth—layered security (firewalls, encryption, IDS, VPNs) to minimize attack surfaces.


2. Firewalls: The First Line of Defense

A firewall is a network security device that monitors and controls incoming/outgoing traffic based on predefined rules. It sits between:

[Untrusted Network (Internet)]
       ↓
[Firewall]
       ↓
[Trusted Network (Internal LAN)]

How Firewalls Work

Firewalls use rulesets (Access Control Lists, ACLs) to:

  1. Inspect packets: Check headers (source/destination IP, port, protocol).
  2. Apply policies: Allow/deny based on rules (e.g., "Block all traffic from IP 192.168.1.100").
  3. Log activity: Record blocked/allowed traffic for auditing.

Types of Firewalls

Type Inspection Level Example Use Case Pros Cons
Packet-Filtering Headers (IP, port, protocol) Blocking ICMP (ping) from external networks Fast, low overhead No payload inspection (vulnerable to spoofing)
Stateful Inspection Connection state (TCP handshake) Allowing established HTTP sessions Tracks context (e.g., SYN floods) Complex rule management
Application-Level Payload (HTTP, FTP, SMTP) Blocking SQL injection in web apps Deep inspection (e.g., malware) High resource usage
Next-Gen (NGFW) Deep packet inspection (DPI) Detecting encrypted threats (TLS) AI-driven threat detection Expensive, complex setup

WORKED EXAMPLE: Blocking a Malicious IP in a Bank Scenario: A Nepali bank’s firewall must block a known fraudster’s IP (203.123.45.67) while allowing legitimate traffic. ACL Rule:

deny ip any host 203.123.45.67
permit ip any any

Trace:

  1. Packet arrives from 203.123.45.67 → Blocked by first rule.
  2. Packet from 192.168.1.10 (internal) → Allowed by second rule.

3. Packet-Level vs. Application-Level Firewalls

Packet-Level Firewall

  • Focus: Headers only (IP, port, protocol).
  • Example: Blocking port 22 (SSH) from external networks.
  • Limitations:
    • Cannot detect encrypted threats (e.g., malware in TLS traffic).
    • Vulnerable to IP spoofing (fake source IPs).

MERMAID DIAGRAM: Packet Filtering

Check Source IPPort 80: AllowPort 22: BlockPacketFirewall (Packet Filter)HTTP ServerSSH Server
Packet-level firewall filtering: Source IP and destination port checks (simplified)

Application-Level Firewall (Proxy Firewall)

  • Focus: Payload inspection (e.g., HTTP headers, SQL queries).
  • Example: Blocking a URL with ?sql=DROP TABLE users in a web request.
  • How it works:
    1. Client request → Proxy server (firewall).
    2. Proxy inspects content → Blocks/Allows.
    3. Response sent back to client.

REAL-WORLD EXAMPLE: eSewa’s Security eSewa uses application-level firewalls to:

  • Block phishing links in payment confirmations.
  • Scan for malicious attachments in transaction emails.
  • Enforce HTTPS (TLS encryption) for all transactions.

4. Access Control Lists (ACLs): The Rule Engine

ACLs define who can access what in a network. Rules are processed top-down; the first match wins.

Rule 1: Allow 192.168.1.0/24 to Port 800Rule 2: Block 10.0.0.0/8 from Port 221Rule 3: Default Deny All2
Example ACL rule order: Rules are evaluated top-down (first match wins)

Standard ACL (Routers):

access-list 10 permit 192.168.1.0 0.0.0.255  // Allow internal subnet
access-list 10 deny ip any any               // Block everything else

Extended ACL (Granular Control):

access-list 110 permit tcp 192.168.1.0 0.0.0.255 any eq 80  // Allow HTTP
access-list 110 deny tcp any any eq 22                          // Block SSH

WORKED EXAMPLE: NTC’s Internet Filter Scenario: NTC wants to block torrent traffic (port 6881) but allow YouTube (HTTPS). Solution:

access-list 120 deny tcp any any eq 6881
access-list 120 permit tcp any any eq 443

5. Intrusion Detection/Prevention Systems (IDS/IPS)

  • IDS: Monitors traffic for suspicious activity (e.g., port scans).
  • IPS: Actively blocks threats (like a firewall + IDS).
MonitorTriggerBlockNetwork TrafficIDS SensorAlert SystemFirewall/IPS
IDS/IPS workflow: Detection → Alerting → Prevention (signature/behavior-based)

How IDS Works:

  1. Signature-based: Matches known attack patterns (e.g., SQLi strings).
  2. Anomaly-based: Flags unusual behavior (e.g., sudden spike in ICMP requests).

REAL-WORLD EXAMPLE: Google’s Security Google uses IPS to:

  • Block DDoS attacks on YouTube.
  • Detect zero-day exploits in Chrome via anomaly detection.

6. Virtual Private Networks (VPNs)

VPNs encrypt traffic over untrusted networks (e.g., public Wi-Fi). Used by:

  • Pathao drivers: Secure GPS/data over mobile networks.
  • Nepali banks: Encrypt ATM transactions.
  • Remote workers: Access corporate networks securely.

How VPNs Work:

  1. Tunneling: Encapsulates data in a secure protocol (IPsec, OpenVPN).
  2. Encryption: Uses AES-256 or RSA to scramble data.
  3. Authentication: Verifies users via certificates or passwords.

MERMAID DIAGRAM: VPN Tunnel

ClientVPN Encryption LayerInternetVPN ServerCorporate LAN
VPN tunnel structure: Data is encrypted between client and VPN server before reaching the corporate network

7. Common Security Threats & Mitigations

Threat Description Mitigation
DDoS Overwhelms servers with traffic Rate limiting, IPS
Phishing Fake emails/websites to steal credentials User training, email filtering
Man-in-the-Middle Eavesdropping on unencrypted traffic VPNs, HTTPS, WPA3
SQL Injection Malicious SQL queries Input validation, WAF
Zero-Day Exploits Unknown vulnerabilities Patch management, IDS/IPS

## In the Real World

  1. eSewa’s Payment Security

    • Idea: Application-level firewall + VPN
    • How: Blocks fraudulent transactions via real-time payload inspection (e.g., duplicate payment attempts). Uses TLS 1.3 for encryption over public networks.
  2. Nepali Banks’ ATM Networks

    • Idea: Stateful firewalls + IDS
    • How: Firewalls block brute-force attacks on ATM PINs, while IDS detects skimming devices via unusual transaction patterns.
  3. Pathao’s Driver App

    • Idea: VPN for GPS Data
    • How: Encrypts driver location data to prevent hackers from tracking vehicles in real-time.
  4. NTC’s Internet Filtering

    • Idea: Extended ACLs
    • How: Blocks pirate sites (e.g., port 6881 for torrents) while allowing educational content (e.g., port 443 for HTTPS).
  5. Google’s Gmail Security

    • Idea: Next-Gen Firewall (NGFW)
    • How: Uses AI to detect phishing emails and blocks malicious attachments before they reach users.

## Exam Tip

What Examiners Look For:

  1. Definitions: Clearly distinguish between packet-level (headers) and application-level (payload) firewalls.
  2. ACL Rules: Write correct syntax (e.g., deny ip any host X.X.X.X) and explain the order of processing.
  3. Real-World Links: Relate concepts to Nepali examples (e.g., "How would a bank configure a firewall to block fraud?").
  4. Threat Mitigations: Match threats (DDoS, SQLi) to specific tools (IPS, WAF, VPNs).
  5. Diagrams: Draw firewall placement (between trusted/untrusted networks) or VPN tunnels in exams.

Common Mistakes to Avoid:

  • Confusing stateful inspection (tracks connections) with stateless (packet-by-packet).
  • Forgetting ACLs are processed top-down (first match wins).
  • Ignoring encryption in VPNs (always mention AES/RSA).

Sample Exam Question & Answer: Q: "Explain how a stateful firewall protects against a SYN flood attack." A:

  1. Normal TCP Handshake:
    Client (SYN) → Server (SYN-ACK) → Client (ACK) → Connection established
    
  2. SYN Flood Attack: Attacker sends SYN packets but never completes the handshake, exhausting server resources.
  3. Stateful Firewall Defense:
    • Tracks SYN-ACK responses waiting for ACKs.
    • Drops new SYNs if the server’s half-open connection limit is reached.
    • Uses SYN cookies (server sends cryptographic token instead of SYN-ACK) to mitigate attacks.

## Quick Revision Checklist

  • Can you draw a firewall placement diagram (trusted vs. untrusted)?
  • Write an ACL rule to block a specific IP.
  • Differentiate IDS vs. IPS (monitor vs. block).
  • Explain VPN tunneling with a diagram.
  • Name 3 Nepali real-world uses of firewalls/VPNs (eSewa, banks, NTC).
  • List 2 threats and their mitigations (e.g., DDoS → rate limiting).

Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 5.

Discussion

Loading…