Comprehensive Overview of Firewalls
Definition of a Firewall
- A firewall is a system designed to prevent unauthorized access from entering a private network by filtering information from the internet.
- Functions of a Firewall:
- Blocks unwanted traffic.
- Permits wanted traffic.
- Purpose: To create a safety barrier between a private network and the public internet.
Importance of a Firewall
- Threat Landscape:
- The internet has hackers and malicious traffic attempting to infiltrate private networks to cause harm.
- Role of Firewalls:
- A firewall acts as the main component on a network to prevent unauthorized access.
- Especially critical for large organizations with multiple computers and servers.
- Prevents all devices from being accessible to everyone on the internet.
- Protects organizations from disruptions caused by hackers.
Analogy: Building Firewalls vs. Network Firewalls
- How firewalls work in building structures:
- A building firewall provides a barrier to contain fires, preventing them from spreading to the other side.
- Without a firewall, a fire would spread, endangering the entire structure.
- Similarities with Network Firewalls:
- Network firewalls stop harmful activities before they can spread and cause damage to a private network.
Functionality of a Firewall
- Data Filtering and Access Control:
- A firewall filters incoming network data to determine if it is allowed to enter, based on customized rules known as an access control list.
- The network administrator defines these rules, determining what can enter and exit the network.
- Example of Access Control List:
- Shows a list of IP addresses either permitted or denied access to the network.
- Traffic from allowed IP addresses can enter, while blocked traffic is denied entry.
- Rule Specifications:
- Rules can be set based on:
- IP addresses
- Domain names
- Protocols
- Programs
- Ports
- Keywords
- Port-Based Rules Example:
- Incoming data allowed through ports: 80 (HTTP), 25 (SMTP), and 110 (POP3).
- Incoming data denied through ports: 23 (Telnet) and 3389 (Remote Desktop).
Types of Firewalls
Host-Based Firewall
- Definition:
- A software firewall installed on an individual computer that protects only that specific device.
- Examples:
- Built-in firewalls in later versions of Microsoft operating systems.
- Third-party software firewalls, such as Zone Alarm.
- Many antivirus programs include built-in host-based firewalls.
Network-Based Firewall
- Definition:
- A combination of hardware and software operating at the network layer, protecting an entire network.
- Operation:
- Positioned between a private network and the public internet.
- Applies management rules to the entire network to stop harmful activity preemptively.
- Variations:
- Standalone products primarily used by large organizations.
- Built-in components of routers, commonly utilized by smaller organizations.
- Implemented in service provider cloud infrastructures.
Combined Use of Firewalls
- Many organizations employ both
- Network-Based Firewalls for overarching network protection.
- Host-Based Firewalls for individual device protection.
- Benefits of Combined Usage:
- Maximum protection for the network.
- If harmful data breaches the network firewall, host-based firewalls can still mitigate risks.