Firewalls
Firewalls
A network firewall is a barrier that intercepts and inspects traffic moving from one area of the network to another. Nearly all networks today benefit from the protection of some type of firewall. In all likelihood, you passed through several firewalls when you opened this material. You probably have a firewall at home that allows you to access the internet while simultaneously preventing intruders from accessing your home network. The servers hosting this material are also protected by a firewall that limits the type of internet traffic that can reach them.
Firewalls come in a variety of forms and provide a range of functionality. Some may be physical appliances mounted in data centers, while others may be virtual appliances operating as VMs (virtual machines). Still, there are others known as host-based firewalls that operate as applications running on workstations and servers. They all have something in common though; they have a set of rules that define whether the firewall will permit or deny the traffic to pass on to its intended destination. In the following sections you will explore firewall types, functionality, and terminology.
Diagram. Packet filtering in the OSI model.
Packet Filters
A packet filter is a firewall that operates at Layers 3 and 4 of the OSI network model: network and transport.
In most networks today, that equates to the IP address (Layer 3) and the TCP or UDP port number (Layer 4) of the traffic passing through the firewall. These firewalls inspect incoming (ingress) and outgoing (egress) traffic and compare the following attributes to a database of packet filter rules that determine if the firewall will forward (allow) or drop (deny) the traffic:
- Protocol (typically IP)
- Source IP Address
- Destination IP Address
- Source TCP or UDP port number
- Destination TCP or UDP port number
These firewalls are only concerned with the address label (header) of the packets and perform no level of inspection on the contents of the packet (the payload). This means that potentially dangerous payloads could pass through a packet filter without being detected as long as the source and destination values were approved by the firewall rules.
Circuit-Level Gateways
A circuit-level gateway is a device that operates as a middleman between two or more systems to help conceal the true identity of the client and server. The gateway may change the IP address and the TCP/UDP port number of the traffic to allow two networks to communicate that otherwise could not (for example, your home network and the internet).
Circuit-level gateways are the foundation of network address translation (NAT) and port address translation (PAT), which are commonly used in firewalls to allow private IP address ranges to communicate on the internet.
Diagram. A stateful firewall in the OSI model.
Stateful Inspection
To help you understand the significance of stateful inspection in firewalls, you must first understand the meaning of the term state. In this context, the word state refers to the connection state of a conversation between two computers. Some protocols, such as TCP, require that the recipient of a message respond back to the sender with an acknowledgment that it received the data. In a packet filter firewall, this would require at least two firewall rules: one that allows the sender to transmit data to the recipient, and another that allows the recipient to respond (acknowledge) back to the sender. Now consider the implications of a sender communicating with many recipients. There is still one rule for the sender, but now there are many rules for the acknowledgments because each recipient requires a rule to respond to the sender.
To reduce the number of firewall rules needed to support TCP communication, firewall vendors implemented a feature known as stateful inspection. This feature allows a firewall to identify traffic as conversational and automatically create temporary firewall rules to permit the response traffic to flow back to the sender. In this way, instead of maintaining a multitude of rules, in a firewall with stateful inspection, you only need to create a firewall rule that allows the communication to begin.
Application Level
Remember, packet filter firewalls lack the ability to inspect the contents of the packets. Because of this, malicious traffic could pass into the network unchecked. To combat this potential weakness in security, network administrators began using proxy servers that could act as a middleman, reading and parsing the traffic payload, and then forwarding it on to the intended destination if the payload was safe. This behavior was later incorporated into firewalls to provide a deeper level of inspection. Firewalls with this ability are commonly called application-aware firewalls, or Layer-7 firewalls because application is the seventh layer of the OSI model.
\n