Comprehensive Overview of Firewalls

Definition of a Firewall

  • A firewall is a system designed to prevent unauthorized access from entering a private network by filtering information from the internet.
  • Functions of a Firewall:
    • Blocks unwanted traffic.
    • Permits wanted traffic.
  • Purpose: To create a safety barrier between a private network and the public internet.

Importance of a Firewall

  • Threat Landscape:
    • The internet has hackers and malicious traffic attempting to infiltrate private networks to cause harm.
  • Role of Firewalls:
    • A firewall acts as the main component on a network to prevent unauthorized access.
    • Especially critical for large organizations with multiple computers and servers.
    • Prevents all devices from being accessible to everyone on the internet.
    • Protects organizations from disruptions caused by hackers.

Analogy: Building Firewalls vs. Network Firewalls

  • How firewalls work in building structures:
    • A building firewall provides a barrier to contain fires, preventing them from spreading to the other side.
    • Without a firewall, a fire would spread, endangering the entire structure.
  • Similarities with Network Firewalls:
    • Network firewalls stop harmful activities before they can spread and cause damage to a private network.

Functionality of a Firewall

  • Data Filtering and Access Control:
    • A firewall filters incoming network data to determine if it is allowed to enter, based on customized rules known as an access control list.
    • The network administrator defines these rules, determining what can enter and exit the network.
  • Example of Access Control List:
    • Shows a list of IP addresses either permitted or denied access to the network.
    • Traffic from allowed IP addresses can enter, while blocked traffic is denied entry.
  • Rule Specifications:
    • Rules can be set based on:
    • IP addresses
    • Domain names
    • Protocols
    • Programs
    • Ports
    • Keywords
  • Port-Based Rules Example:
    • Incoming data allowed through ports: 80 (HTTP), 25 (SMTP), and 110 (POP3).
    • Incoming data denied through ports: 23 (Telnet) and 3389 (Remote Desktop).

Types of Firewalls

Host-Based Firewall

  • Definition:
    • A software firewall installed on an individual computer that protects only that specific device.
  • Examples:
    • Built-in firewalls in later versions of Microsoft operating systems.
    • Third-party software firewalls, such as Zone Alarm.
    • Many antivirus programs include built-in host-based firewalls.

Network-Based Firewall

  • Definition:
    • A combination of hardware and software operating at the network layer, protecting an entire network.
  • Operation:
    • Positioned between a private network and the public internet.
    • Applies management rules to the entire network to stop harmful activity preemptively.
  • Variations:
    • Standalone products primarily used by large organizations.
    • Built-in components of routers, commonly utilized by smaller organizations.
    • Implemented in service provider cloud infrastructures.

Combined Use of Firewalls

  • Many organizations employ both
    • Network-Based Firewalls for overarching network protection.
    • Host-Based Firewalls for individual device protection.
  • Benefits of Combined Usage:
    • Maximum protection for the network.
    • If harmful data breaches the network firewall, host-based firewalls can still mitigate risks.