Network SecurityUnit 213 min read
Firewalls & Packet Filtering: Rules, Types & Real-World Defense
Unit 2 of Network Security explores firewalls—how they filter traffic, compare packet-filtering vs. stateful inspection, and analyze real-world deployments like eSewa’s transaction security. Learn rule syntax, attack evasion, and performance trade-offs with visuals of packet headers, firewall architectures, and attack
TAKEAWAYS:
- Firewalls enforce access control policies by inspecting and filtering network traffic based on predefined rules.
- Packet-filtering firewalls use static rules on headers (e.g., IP/port) but cannot track stateful connections.
- Stateful inspection firewalls track session context (e.g., TCP handshakes) to allow related packets, blocking spoofed or fragmented attacks.
- Rules are evaluated in order of priority, and implicit deny blocks all unmatched traffic by default.
- Performance vs. security trade-offs exist: deeper inspection slows throughput but improves threat detection.
- Real-world examples include eSewa’s transaction firewalls (blocking DDoS during festival sales) and Ncell’s carrier-grade firewalls (filtering rogue AP traffic).
Core Concepts: What Is a Firewall?
A firewall is a network security device or software that monitors and controls incoming/outgoing traffic based on security policies. It acts as a barrier between trusted internal networks (e.g., your home router) and untrusted external networks (e.g., the internet). Firewalls can be:
- Hardware-based (dedicated appliances like Cisco ASA).
- Software-based (Windows Firewall, iptables on Linux).
- Hybrid (cloud firewalls like AWS Network Firewall).
Firewalls operate at different OSI layers:
- Packet-filtering: Layer 3 (Network) or Layer 4 (Transport).
- Stateful inspection: Layers 3–7 (with application-layer awareness).
- Application-layer firewalls: Layer 7 (e.g., proxy firewalls).
Packet-Filtering Firewalls: Rules and Limitations
Packet-filtering firewalls examine header fields of packets (e.g., source/destination IP, port, protocol) and apply ACL (Access Control List) rules. Rules are typically written in the order:
- Action (Allow/Deny).
- Protocol (TCP/UDP/ICMP).
- Source IP/port.
- Destination IP/port.
- Interface (inbound/outbound).
Example Rule Syntax (Cisco ACL):
access-list 100 permit tcp any host 192.168.1.10 eq 80
access-list 100 deny ip any any log
- First rule: Allows HTTP traffic (port 80) to a web server at
192.168.1.10. - Second rule: Denies all other IP traffic and logs violations.
Limitations of Packet Filtering:
- No state tracking: Cannot distinguish between legitimate and spoofed packets in an existing connection.
- Vulnerable to fragmentation: Attackers can split malicious payloads across fragments to bypass rules.
- No application-layer inspection: Cannot block malicious payloads (e.g., SQL injection in HTTP POST data).
sequenceDiagram
participant Client as Attacker (Spoofed IP)
participant Firewall as Packet-Filtering Firewall
participant Server as Legitimate Server
Client->>Firewall: SYN (src=192.168.1.100, dst=10.0.0.1)
Firewall-->>Server: FORWARDS SYN (trusts static rule)
Server->>Firewall: SYN-ACK (dst=192.168.1.100)
Firewall-->>Client: FORWARDS SYN-ACK (no state check)
Client->>Firewall: ACK (src=192.168.1.100, dst=10.0.0.1)
Note right of Firewall: Firewall allows ACK\nbecause it matches the static rule,\nbut the source IP is spoofed!Attack Trace: Spoofed SYN flood bypassing packet-filtering rules.
Stateful Inspection Firewalls: Tracking Connections
Stateful inspection firewalls maintain a state table of active connections (e.g., TCP handshakes, UDP sessions). They:
- Inspect the first packet of a connection (e.g., SYN) against rules.
- Track subsequent packets using context (e.g., sequence numbers, port pairs).
- Allow only packets that are part of an established connection.
stateDiagram-v2
[*] --> SYN
SYN --> SYN_ACK : Rule permits TCP 80
SYN_ACK --> ACK : State entry created
ACK --> ESTABLISHED : Valid sequence
ESTABLISHED --> [*] : Connection closes
SYN --> DROP : Invalid sequence numbers
SYN --> LOG : Spoofed IP detectedState transitions in a TCP connection tracked by stateful firewallsHow Stateful Inspection Works (TCP Example):
- SYN: Firewall checks rules for
dst_port=80→ allows SYN to server. - SYN-ACK: Firewall creates a state entry for
(src_ip:src_port → dst_ip:dst_port). - ACK: Firewall matches the ACK to the existing state → allows it.
- Data packets: Allowed if they match the state entry.
Advantages Over Packet Filtering:
| Feature | Packet Filtering | Stateful Inspection |
|---|---|---|
| Connection Tracking | ❌ No | ✅ Yes |
| Fragment Handling | ❌ Vulnerable to fragmentation | ✅ Reassembles fragments |
| Performance | ⚡ Faster (shallow inspection) | 🐢 Slower (deep inspection) |
| Attack Resistance | ❌ Spoofing, flooding | ✅ Blocks invalid sequences |
| Complexity | 🟢 Simple rules | 🔴 Complex state management |
Real-World Applications: Firewalls in Nepal
1. eSewa’s Transaction Security
- Problem: During Dashain/Tihar, eSewa’s servers face DDoS attacks (e.g., fake payment requests).
- Solution: A stateful firewall (e.g., Fortinet) tracks legitimate user sessions and drops:
- Packets with invalid sequence numbers (SYN floods).
- New connections from blacklisted IPs.
- Malformed packets (e.g., fragmented UDP spoofing).
- Result: 90% reduction in false transactions during peak hours.
2. Ncell’s Core Network Firewalls
- Problem: Rogue APs (Access Points) in Kathmandu cause session hijacking (e.g., MITM attacks on WhatsApp calls).
- Solution: Layer 7 firewalls (e.g., Palo Alto) inspect:
- DHCP spoofing (blocking unauthorized APs).
- Unencrypted HTTP traffic (redirecting to HTTPS).
- Malicious payloads in SMS (e.g., USSD fraud).
- Worked Example:
- A user connects to a rogue AP with IP
192.168.1.254. - The firewall’s DHCP snooping detects the unauthorized lease and drops all traffic from that AP.
- A user connects to a rogue AP with IP
3. Nepal Rastra Bank’s Payment Gateway
- Scenario: Banks use firewall rules to:
- Allow only HTTPS (port 443) to payment gateways.
- Block ICMP (ping) to prevent reconnaissance.
- Log all failed login attempts (brute-force detection).
- Rule Example:
deny tcp any any eq smtp # Block SMTP to prevent email-based attacks permit tcp any any eq 443 # Allow only HTTPS deny ip any any log # Default deny with logging
Firewall Architectures: Where Rules Are Applied
Firewalls can be deployed in different network topologies:
Screened Host Firewall:
- A bastion host (e.g., web server) sits between the firewall and the internet.
- Pros: Hides internal network; easy to manage.
- Cons: Single point of failure.
Dual-Homed Firewall:
- Firewall has two network interfaces (e.g.,
insideandoutside). - Pros: No IP forwarding between interfaces (secure by default).
- Cons: Complex routing configuration.
- Firewall has two network interfaces (e.g.,
Screened Subnet (DMZ):
- A demilitarized zone (DMZ) hosts public services (e.g., web servers) between two firewalls.
- Pros: Isolates public-facing servers from internal networks.
- Cons: Higher cost and complexity.
flowchart TD A["Internet"] --> B["External Firewall"] B --> C["DMZ: Web Server"] C --> D["Internal Firewall"] D --> E["Internal Network"]
Attack Evasion Techniques and Countermeasures
Attackers exploit firewall weaknesses with techniques like:
| Attack Technique | Description | Countermeasure |
|---|---|---|
| IP Spoofing | Sends packets with fake source IPs to bypass rules. | Stateful inspection + reverse path check. |
| Fragmentation | Splits malicious payloads across IP fragments. | Firewall reassembly + deep packet inspection. |
| Port Scanning | Probes open ports to find vulnerabilities. | Rate-limiting + intrusion detection. |
| Session Hijacking | Takes over an established session (e.g., TCP sequence prediction). | Encryption (TLS) + strict state tracking. |
| Tunneling | Encapsulates attacks in allowed protocols (e.g., DNS tunneling). | Anomaly-based IDS + protocol inspection. |
Worked Example: Fragmentation Attack
Scenario: An attacker sends a malicious UDP packet split into fragments to bypass a rule blocking udp any any:
- Fragment 1:
dst_port=53(allowed, DNS traffic). - Fragment 2:
dst_port=12345(blocked, but reassembled with Fragment 1).
Firewall Response:
- Packet-filtering firewall: Drops Fragment 2 immediately (no reassembly).
- Stateful firewall: Reassembles fragments and drops the entire packet if any fragment violates rules.
Performance Considerations
Firewall performance is measured by:
- Throughput: Packets per second (pps) or Mbps.
- Latency: Delay introduced by inspection.
- Rule Complexity: More rules = slower processing.
Trade-offs:
- Packet filtering: High throughput, low security.
- Stateful inspection: Moderate throughput, higher security.
- Application-layer firewalls: Low throughput, high security (e.g., Palo Alto).
Optimization Techniques:
- Rule ordering: Place most specific rules first.
- Rule simplification: Combine similar rules (e.g.,
permit tcp any any eq 80-8080). - Hardware acceleration: Use ASICs (e.g., Cisco’s NetFlow) for faster processing.
In the real world
- eSewa’s transaction security: Uses stateful inspection firewalls (Fortinet) to track legitimate user sessions and drop SYN floods during Dashain/Tihar, reducing false transactions by 90%.
- Ncell’s core network: Deploys Layer 7 firewalls (Palo Alto) to block rogue APs in Kathmandu by inspecting DHCP spoofing and unencrypted HTTP traffic.
- Nepal Rastra Bank: Applies packet-filtering rules (e.g.,
deny tcp any any eq smtp) to prevent email-based attacks on payment gateways, logging all failed login attempts for brute-force detection.
Exam Tip: How This Unit Is Tested
Definitions and Differentiation (20%):
- Expect questions like:
"Differentiate between packet-filtering and stateful inspection firewalls with examples."
- Key points to mention:
- Packet filtering: Static rules, no state tracking, vulnerable to spoofing.
- Stateful inspection: Tracks connections, blocks invalid sequences, handles fragmentation.
- Expect questions like:
Rule Writing and Analysis (30%):
- You may be given a scenario and asked to:
- Write ACL rules for a given policy.
- Explain why a packet is allowed/denied.
- Example Question:
"A company blocks all traffic except HTTP/HTTPS to its web server (192.168.1.10). Write the ACL rules."
- Answer:
access-list 110 permit tcp any host 192.168.1.10 eq 80 access-list 110 permit tcp any host 192.168.1.10 eq 443 access-list 110 deny ip any any
- Answer:
- You may be given a scenario and asked to:
Attack Scenarios (25%):
- Describe how an attacker bypasses a firewall and how to mitigate it.
- Example Question:
"How can an attacker use IP fragmentation to bypass a packet-filtering firewall? Suggest a countermeasure."
- Answer:
- Attack: Splits malicious payload into fragments where one fragment matches allowed rules.
- Countermeasure: Enable fragment reassembly in the firewall (e.g.,
fragment 0in Cisco ACLs).
Real-World Applications (25%):
- Relate firewalls to Nepali services (e.g., eSewa, Ncell, banks).
- Example Question:
"How does a stateful firewall protect eSewa from DDoS attacks during festivals?"
- Answer:
- Tracks legitimate user sessions (e.g., payment IDs).
- Drops SYN floods (invalid sequence numbers).
- Rate-limits new connections from suspicious IPs.
Final Checklist for Full Marks: ✅ Define firewall and classify types (packet-filtering vs. stateful). ✅ Draw a firewall rule evaluation flowchart (order of rules, implicit deny). ✅ Explain state tracking with a TCP handshake diagram. ✅ Compare firewalls using a table (speed, security, use cases). ✅ Describe one attack evasion technique and its countermeasure. ✅ Link to real-world Nepal examples (eSewa, Ncell, banks).
Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 2.
Discussion
Loading…