Firewalls Explained - Packet Filtering to NGFW
About 2 min read
A firewall is a security mechanism placed at the boundary of a network to block unauthorized access and communication. It monitors traffic between external and internal networks and decides whether to allow or deny it based on predefined rules. Firewalls are built not only into corporate networks but also into personal PCs and home routers.
Types of Firewalls
Packet-filtering firewalls are the most basic type, controlling traffic based on IP addresses and port numbers. Stateful inspection firewalls track the state of connections and make more sophisticated decisions, such as allowing only packets that belong to established connections. Next-generation firewalls (NGFW) inspect all the way up to the application layer and can detect malware and malicious content. Some NGFW products also offer threat detection driven by AI/machine learning, used to flag traffic that matches no known signature as anomalous, although how much it actually catches depends on the product and how it is operated. Web application firewalls (WAF) specialize in HTTP/HTTPS traffic and defend against web attacks such as SQL injection and XSS.
What Outbound Traffic Logs Can Reveal
Firewalls are not only for blocking traffic that comes in from the outside. Reviewing NGFW logs for traffic going from the inside out can surface a device that repeatedly connects at regular intervals to a destination that has nothing to do with work. Such traffic may be malware C2 (command-and-control) communication, in which case the flow is to deny traffic to that destination, isolate the device from the network, and then check whether it is infected.
Examples of How Individual Traffic Is Allowed or Denied
Traffic that crosses the boundary between the external and internal networks is judged one item at a time, as follows. What the firewall is able to look at differs depending on its type.
| Example of traffic | What the decision is based on | Type that can make the call | Verdict |
|---|---|---|---|
| A connection arriving from outside that no internal PC asked for | The packet does not belong to an established connection | Stateful inspection | Deny |
| The response to communication an internal PC initiated itself | The packet belongs to an established connection | Stateful inspection | Allow |
| Traffic to a port number that is not used for work | The IP address and the port number | Packet filtering | Deny |
| A file download that contains malware | The contents, inspected up to the application layer | Next-generation firewall (NGFW) | Deny |
| A request to a web app that attempts SQL injection | The contents of the HTTP/HTTPS request | Web application firewall (WAF) | Deny |
| Malware C2 traffic going from the inside to the outside | The direction of the traffic and how suspicious the destination in the logs is | Log analysis on a next-generation firewall (NGFW) | Deny and isolate the device |
How traffic that is not listed in the table gets handled depends on the configuration. Under the principle of least privilege, the starting point is a configuration that permits only the necessary communication and denies everything else.
Concrete Usage Scenarios
In a home environment, the router's built-in firewall blocks unauthorized access from the outside and protects IoT devices from attacks. In a corporate environment, firewalls separate networks between departments, preventing the spread of damage in the event of an intrusion. In a cloud environment, security groups and network ACLs serve the role of firewalls, controlling access to instances. In a remote-work environment, combining a VPN with a firewall enables secure access to internal resources.
Practical Considerations
A firewall provides defense at the network layer, but password strength is also essential for protecting accounts. Even if the firewall is breached, a strong random password serves as the last line of defense. A common pitfall is setting firewall rules to "allow everything for now." Based on the principle of least privilege, it is important to configure rules that permit only the necessary communication. In line with the concept of defense in depth, be thorough with both network defense and password management.
Was this article helpful?