Network and System AdministrationUnit 511 min read
Network Security & Firewalls: Types, Rules, Real-World Use
Unit 5 of Network and System Administration explores firewalls (packet-level vs. application-level), security threats, access control lists (ACLs), intrusion detection systems (IDS), and VPNs—with real-world examples from Nepali banks, eSewa, and global tech giants like Google. Learn how firewalls filter traffic, how A
TAKEAWAYS:
- Firewalls act as gatekeepers between trusted internal networks and untrusted external ones, filtering traffic based on rules (ACLs) to block malicious activity.
- Packet-level firewalls inspect headers (source/destination IP, ports) while application-level firewalls analyze payloads (e.g., SQL queries, HTTP content).
- Security threats like DDoS, phishing, and man-in-the-middle attacks exploit vulnerabilities; firewalls, IDS/IPS, and VPNs mitigate these risks.
- Access Control Lists (ACLs) define granular permissions (e.g., allow HTTP/HTTPS, block ICMP) to enforce security policies.
- VPNs encrypt traffic over public networks (e.g., Pathao drivers using mobile data) to ensure confidentiality and integrity.
- Real-world tie-ins: Nepali banks use firewalls to block fraudulent transactions, eSewa encrypts payments via VPNs, and Google’s Gmail filters spam with application-level firewalls.
1. Why Network Security Matters
Networks are target-rich environments for attackers. Without security measures, threats like:
- Unauthorized access (e.g., hackers exploiting weak passwords).
- Data breaches (e.g., customer records stolen from Daraz’s database).
- Denial-of-Service (DoS/DDoS) (e.g., overwhelming NTC’s servers to disrupt internet).
- Malware (e.g., ransomware locking NEPSE’s trading systems).
Solution: Defense in depth—layered security (firewalls, encryption, IDS, VPNs) to minimize attack surfaces.
2. Firewalls: The First Line of Defense
A firewall is a network security device that monitors and controls incoming/outgoing traffic based on predefined rules. It sits between:
[Untrusted Network (Internet)]
↓
[Firewall]
↓
[Trusted Network (Internal LAN)]
How Firewalls Work
Firewalls use rulesets (Access Control Lists, ACLs) to:
- Inspect packets: Check headers (source/destination IP, port, protocol).
- Apply policies: Allow/deny based on rules (e.g., "Block all traffic from IP
192.168.1.100"). - Log activity: Record blocked/allowed traffic for auditing.
Types of Firewalls
| Type | Inspection Level | Example Use Case | Pros | Cons |
|---|---|---|---|---|
| Packet-Filtering | Headers (IP, port, protocol) | Blocking ICMP (ping) from external networks | Fast, low overhead | No payload inspection (vulnerable to spoofing) |
| Stateful Inspection | Connection state (TCP handshake) | Allowing established HTTP sessions | Tracks context (e.g., SYN floods) | Complex rule management |
| Application-Level | Payload (HTTP, FTP, SMTP) | Blocking SQL injection in web apps | Deep inspection (e.g., malware) | High resource usage |
| Next-Gen (NGFW) | Deep packet inspection (DPI) | Detecting encrypted threats (TLS) | AI-driven threat detection | Expensive, complex setup |
WORKED EXAMPLE: Blocking a Malicious IP in a Bank
Scenario: A Nepali bank’s firewall must block a known fraudster’s IP (203.123.45.67) while allowing legitimate traffic.
ACL Rule:
deny ip any host 203.123.45.67
permit ip any any
Trace:
- Packet arrives from
203.123.45.67→ Blocked by first rule. - Packet from
192.168.1.10(internal) → Allowed by second rule.
3. Packet-Level vs. Application-Level Firewalls
Packet-Level Firewall
- Focus: Headers only (IP, port, protocol).
- Example: Blocking port
22(SSH) from external networks. - Limitations:
- Cannot detect encrypted threats (e.g., malware in TLS traffic).
- Vulnerable to IP spoofing (fake source IPs).
MERMAID DIAGRAM: Packet Filtering
Application-Level Firewall (Proxy Firewall)
- Focus: Payload inspection (e.g., HTTP headers, SQL queries).
- Example: Blocking a URL with
?sql=DROP TABLE usersin a web request. - How it works:
- Client request → Proxy server (firewall).
- Proxy inspects content → Blocks/Allows.
- Response sent back to client.
REAL-WORLD EXAMPLE: eSewa’s Security eSewa uses application-level firewalls to:
- Block phishing links in payment confirmations.
- Scan for malicious attachments in transaction emails.
- Enforce HTTPS (TLS encryption) for all transactions.
4. Access Control Lists (ACLs): The Rule Engine
ACLs define who can access what in a network. Rules are processed top-down; the first match wins.
Standard ACL (Routers):
access-list 10 permit 192.168.1.0 0.0.0.255 // Allow internal subnet
access-list 10 deny ip any any // Block everything else
Extended ACL (Granular Control):
access-list 110 permit tcp 192.168.1.0 0.0.0.255 any eq 80 // Allow HTTP
access-list 110 deny tcp any any eq 22 // Block SSH
WORKED EXAMPLE: NTC’s Internet Filter Scenario: NTC wants to block torrent traffic (port 6881) but allow YouTube (HTTPS). Solution:
access-list 120 deny tcp any any eq 6881
access-list 120 permit tcp any any eq 443
5. Intrusion Detection/Prevention Systems (IDS/IPS)
- IDS: Monitors traffic for suspicious activity (e.g., port scans).
- IPS: Actively blocks threats (like a firewall + IDS).
How IDS Works:
- Signature-based: Matches known attack patterns (e.g., SQLi strings).
- Anomaly-based: Flags unusual behavior (e.g., sudden spike in ICMP requests).
REAL-WORLD EXAMPLE: Google’s Security Google uses IPS to:
- Block DDoS attacks on YouTube.
- Detect zero-day exploits in Chrome via anomaly detection.
6. Virtual Private Networks (VPNs)
VPNs encrypt traffic over untrusted networks (e.g., public Wi-Fi). Used by:
- Pathao drivers: Secure GPS/data over mobile networks.
- Nepali banks: Encrypt ATM transactions.
- Remote workers: Access corporate networks securely.
How VPNs Work:
- Tunneling: Encapsulates data in a secure protocol (IPsec, OpenVPN).
- Encryption: Uses AES-256 or RSA to scramble data.
- Authentication: Verifies users via certificates or passwords.
MERMAID DIAGRAM: VPN Tunnel
7. Common Security Threats & Mitigations
| Threat | Description | Mitigation |
|---|---|---|
| DDoS | Overwhelms servers with traffic | Rate limiting, IPS |
| Phishing | Fake emails/websites to steal credentials | User training, email filtering |
| Man-in-the-Middle | Eavesdropping on unencrypted traffic | VPNs, HTTPS, WPA3 |
| SQL Injection | Malicious SQL queries | Input validation, WAF |
| Zero-Day Exploits | Unknown vulnerabilities | Patch management, IDS/IPS |
## In the Real World
eSewa’s Payment Security
- Idea: Application-level firewall + VPN
- How: Blocks fraudulent transactions via real-time payload inspection (e.g., duplicate payment attempts). Uses TLS 1.3 for encryption over public networks.
Nepali Banks’ ATM Networks
- Idea: Stateful firewalls + IDS
- How: Firewalls block brute-force attacks on ATM PINs, while IDS detects skimming devices via unusual transaction patterns.
Pathao’s Driver App
- Idea: VPN for GPS Data
- How: Encrypts driver location data to prevent hackers from tracking vehicles in real-time.
NTC’s Internet Filtering
- Idea: Extended ACLs
- How: Blocks pirate sites (e.g., port
6881for torrents) while allowing educational content (e.g., port443for HTTPS).
Google’s Gmail Security
- Idea: Next-Gen Firewall (NGFW)
- How: Uses AI to detect phishing emails and blocks malicious attachments before they reach users.
## Exam Tip
What Examiners Look For:
- Definitions: Clearly distinguish between packet-level (headers) and application-level (payload) firewalls.
- ACL Rules: Write correct syntax (e.g.,
deny ip any host X.X.X.X) and explain the order of processing. - Real-World Links: Relate concepts to Nepali examples (e.g., "How would a bank configure a firewall to block fraud?").
- Threat Mitigations: Match threats (DDoS, SQLi) to specific tools (IPS, WAF, VPNs).
- Diagrams: Draw firewall placement (between trusted/untrusted networks) or VPN tunnels in exams.
Common Mistakes to Avoid:
- Confusing stateful inspection (tracks connections) with stateless (packet-by-packet).
- Forgetting ACLs are processed top-down (first match wins).
- Ignoring encryption in VPNs (always mention AES/RSA).
Sample Exam Question & Answer: Q: "Explain how a stateful firewall protects against a SYN flood attack." A:
- Normal TCP Handshake:
Client (SYN) → Server (SYN-ACK) → Client (ACK) → Connection established - SYN Flood Attack: Attacker sends SYN packets but never completes the handshake, exhausting server resources.
- Stateful Firewall Defense:
- Tracks SYN-ACK responses waiting for ACKs.
- Drops new SYNs if the server’s half-open connection limit is reached.
- Uses SYN cookies (server sends cryptographic token instead of SYN-ACK) to mitigate attacks.
## Quick Revision Checklist
- Can you draw a firewall placement diagram (trusted vs. untrusted)?
- Write an ACL rule to block a specific IP.
- Differentiate IDS vs. IPS (monitor vs. block).
- Explain VPN tunneling with a diagram.
- Name 3 Nepali real-world uses of firewalls/VPNs (eSewa, banks, NTC).
- List 2 threats and their mitigations (e.g., DDoS → rate limiting).
Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 5.
Discussion
Loading…