Chapter 3: Firewalls
Overview and Core Functions of Firewalls
Firewalls serve as a fundamental security boundary and defensive barrier between an internal network and the outside world (such as the Internet).
Firewalls are critical components required to establish comprehensive network defense.
Core mechanisms provided by firewalls include:
Packet filtering
Stateful packet filtering
User authentication
Client application authentication

Types of Firewalls
Packet Filtering Firewalls
Packet filtering firewalls (also referred to as screening firewalls) represent a basic form of firewall technology that controls traffic by inspecting individual network packets and deciding whether to accept (allow) or reject/drop them.
Filtering rules and standards determine access based on:
Source IP address
Destination IP address
Source port
Destination port
Application protocols and defined rule sets
Filtering operates exclusively by examining packet headers without inspecting the actual payload/data content.
Built-in operating system implementations:
Linux:
NetFilteroperates at the kernel level.Windows: Windows Filtering Platform (
WFP).
Common commercial and standalone packet filtering products:
Firestarter
Avast Internet Security
Zone Alarm Firewall
Comodo Firewall
Required policy rule parameters:
Permitted application protocols (e.g., FTP, SMTP, POP3)
Permitted source ports
Permitted destination ports
Permitted source IP addresses
Disadvantages and limitations:
Stateless operation: Packets are evaluated individually without comparing them against other packets or past context.
Complete lack of user authentication mechanisms.
High susceptibility to Denial of Service (DoS) and flooding attacks, specifically SYN floods and Ping floods.
Fails to track connection states or packet streams.
Inspects header fields only and ignores packet data contents.
Not considered the most secure firewall design when used alone.
Stateful Packet Inspection (SPI)
Context awareness: SPI firewalls evaluate packets within the broader context of established connection streams, making them significantly less susceptible to flood attacks.
Operational capabilities:
Tracks whether an incoming packet belongs to an existing, established connection stream.
Verifies whether the source IP address originates from inside or outside the firewall perimeter.
Inspects the internal data contents and payload of network packets.
Deployment recommendation: SPI is the recommended primary firewall solution whenever available.
Commercial vendors and products:
SonicWALL (
www.sonicwall.com/)Linksys (
www.linksys.com/)Cisco (
www.cisco.com)Comparison resource: Gartner comparison between Cisco and SonicWall (
https://www.gartner.com/reviews/market/network-firewalls/compare/cisco-vs-sonic-wall)Top industry alternatives: Fortinet, Palo Alto, Juniper, Barracuda, Sophos, WatchGuard, and CheckPoint.
Application Gateways
Also known as application proxies, application-level proxies, or Application Layer Gateways (ALG).
Serves as a specialized security component that augments a standard firewall or Network Address Translation (NAT) inside a LAN.
Inspects and manages the specific connection between client and server applications.
Key capabilities:
Verifies client applications.
Allows administrators to explicitly specify which applications are permitted to run.
Provides mechanisms for mandatory user authentication.
Disadvantages and limitations:
Demands significantly more system and processing resources.
Susceptible to flooding attacks (such as SYN and Ping floods) due to the extended time required to authenticate users.
Once a user connection is authenticated and established, individual packets inside that stream are no longer checked.
Product examples:
Teros Application Gateway for web servers (
www.teros.com/products/appliances/gateway/index.shtml)WatchGuard Technologies Firebox (
www.watchguard.com/products/fireboxx.asp)
Circuit-Level Gateways
Establishes a secure virtual circuit between an internal client and a proxy server.
Operates between the Transport and Application layers (specifically at the Session layer), providing TCP and UDP connection security.
Operational security characteristics:
Authenticates user logons prior to establishing a virtual circuit.
Conceals internal topology: External systems interact solely with the proxy server's IP address and cannot discover internal client IP addresses.
Offers greater security than application gateways.
Typically deployed on high-end enterprise network equipment.
May prove incompatible with certain custom or non-standard network implementations.
Software implementation example: Amrita Labs Circuit Level Gateway (
http://aitf.amrita.edu/gw.htm).

Hybrid Firewalls
Hybrid configurations combine multiple distinct firewall techniques into a unified solution.
A common hybrid setup combines Stateful Packet Inspection (SPI) with Circuit-Level Gateways to establish multi-layered inspection controls.
Firewall Implementation Architectures
Implementation Types
Next-Generation Firewalls (NGFWs):
Integrates standard firewall inspection methodologies with Antivirus (AV) scanning and Intrusion Detection Systems (IDS) to perform deep packet inspection.
Network Host-Based Firewalls:
A software-based solution executing directly on top of an existing host operating system.
Inexpensive deployment model that requires rigorous OS hardening:
Ensuring all system security patches are updated.
Uninstalling unnecessary applications and utilities.
Closing all unused network ports.
Disabling all non-essential system services.
Dual-Homed Hosts:
An expanded version of a network host-based firewall utilizing multiple network interfaces.
Executes on top of an OS; its primary weakness is complete reliance on underlying OS security.

Router-Based Firewalls:
Serves as the initial perimeter line of defense.
Implements simple packet filtering rules.
Ideal for novice administrators due to ease of setup, configuration, and availability of vendor pre-configurations.
Can be placed between internal network segments to control inter-segment traffic.
Screened Host Architecture:
Combines a screening router with a dedicated bastion host.
External hosts are forced to connect through the bastion host rather than establishing direct connections to internal network hosts.

Demilitarized Zone (DMZ) Architectures
Purpose: Isolates publicly accessible network services from the private internal network.
Standard Dual-Firewall DMZ Configuration:
Outer Firewall: Directly faces external public traffic.
Inner Firewall: Directly protects internal network endpoints.
DMZ Segment (In-between): Hosts public services such as Web, Email, and FTP servers.
Alternative Deployment: A DMZ can also be implemented using a single firewall hardware appliance configured with three distinct network interfaces.

Defense-in-Depth Architecture (Utmost Security)
Achieving maximum security requires combining multiple layered technologies:
Multi-tier firewalls: Integrating Stateful Packet Inspection (SPI) firewalls alongside Application Gateways.
Dual-perimeter firewall architecture (incorporating a perimeter firewall and optional DMZ).
Screened-firewall routers positioned to separate individual subnetworks (e.g., Subnet 1 and Subnet 2).
Host-based individual packet filtering firewalls installed on every internal server.

Selection, Maintenance, Proxy Servers, and NAT
Firewall Selection and Maintenance
Operational requirements:
Firewalls must be configured properly to provide effective protection.
Security consultants should be considered for initial implementation and rule-base configuration.
System logs must be reviewed periodically to identify anomalies and unauthorized connection attempts.
System statistics should be continuously gathered to establish normal baseline performance metrics.
Proxy Servers
Primary security functions:
Prevents external parties from conducting reconnaissance or gathering internal network information.
Provides detailed log records for audit trails.
Redirects network traffic dynamically based on administrator configuration settings.
Typically executes on the firewall device.
Protects internal endpoints against IP address spoofing attacks.
WinGate Proxy Server:
Supports Internet connection sharing across endpoints.
Hides internal IP addresses from external view.
Incorporates integrated virus scanning features.
Provides Web site content filtering.
Inexpensive, simple to configure, and accessible as a free download.
Network Address Translation (NAT)
Technology that supersedes traditional proxy servers by translating internal private IP addresses to external public IP addresses.
Allows explicit port mapping to direct inbound traffic to specific internal IP addresses (such as local web servers).
Frequently built directly into modern operating systems.
NAT Operational Modes:
Static NAT: Maps a single private IP address to a single static public IP address (used for web hosting services, e.g.,
www.245.com).Dynamic NAT: Maps multiple private IP addresses to an elastic pool of public IP addresses across LAN/WAN boundaries. Used when the total number of concurrent users accessing the Internet at a given point in time is known.