learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Firewalls & Packet Filtering

An ordered list of rules and a default: first match wins, a drop is a timeout, a reject is a refusal, and state is why replies get back in.

An interactive Networking lesson: 21 steps, about 35 minutes, on a live simulation in your browser.

The shop has two machines. web serves the site and must be reachable by anyone. db holds the orders and must be reachable by almost nobody. Between them and the internet stands one machine with three network cards: the firewall.

A customer on the client fetches the home page. It works, and it looks like the firewall did nothing. It did something five times: every packet of that exchange, in both directions, arrived at the firewall and was checked against a list before being passed on.

What you will learn

  1. A list of rules and a default

    • Every packet asks permission: A firewall is a router that checks a list before it forwards. Nothing crosses it without a rule that says so.
    • The list: A firewall is an ordered list of match-and-verdict rules plus one default verdict for packets that match nothing.
    • A packet no rule mentions: Default-deny: what no rule allows is dropped. You list what is permitted, and everything you forgot is closed.
    • Break it: flip the default: Default-allow lists what is forbidden; default-deny lists what is permitted. Only the second list can ever be complete.
  2. To it, through it, from it

    • Three chains, three kinds of packet: INPUT judges packets to the firewall, OUTPUT packets from it, FORWARD packets through it. A packet arriving from outside meets INPUT or FORWARD, never both.
  3. Drop versus reject

    • A reject answers: DROP says nothing, and the sender waits out its retries: a timeout. REJECT answers, and the sender fails at once: connection refused.
    • Refused, but by whom?: Refused means the packet reached something that answered no: the host, or a firewall rejecting on its behalf. Timeout means something on the path discarded it in silence.
  4. First match wins

    • You add a rule. Nothing changes.
    • The counters show which rule fired
    • Same rule, higher up: Rules are read top to bottom and the first match decides. Where a rule sits matters as much as what it says.
    • Drill: insert at a line
  5. Stateful filtering

    • Break it: allow the request, forget the reply
    • The firewall remembers: A stateful firewall decides on the first packet of a connection and remembers it. Your rules say who may start a conversation; the established rule carries the rest, both ways.
    • Replies get out. Can web call out?: Direction belongs to the connection, not the packet: what matters is who sent the first SYN. Replies ride on state; new connections need a rule, whichever side they start from.
  6. The DMZ pattern

    • Three zones, three sentences: A DMZ puts the machines strangers may reach in a network of their own, so that breaking into one still leaves a firewall between the intruder and the data.
    • Break it: trusting an address: A rule that matches only on source hands that machine the whole network. Name source, destination, protocol and port, or you have allowed more than you meant.
    • The finished ruleset
  7. Changing a live firewall

    • Break it: lock yourself out
    • Drill: which rule is eating it?
  8. Recap & playground

    • Cheat sheet
    • Playground