What a network firewall does, and what it cannot stop
Where a network firewall sits, what incoming and outgoing mean depending on who is looking, and the list of things the Week 9 lecture says a firewall cannot protect against.
- Explain where a network firewall is installed and why the placement matters.
- Distinguish the LAN administrator's meaning of incoming and outgoing from the firewall documentation's meaning.
- Distinguish a network firewall from a host-based firewall.
- State the limitations of firewalls the lecture lists and give the reason behind each.
15 min read
Intuition
In a building, a firewall is a wall built to stop a fire spreading from one section to another. The lecture prefers a different picture for a network: the moat of a medieval castle. People may enter at one carefully controlled point and leave at one carefully controlled point, and an attacker is kept from getting close to the other defences.
The idea is a single choke point. If every packet between a trusted network and an untrusted one has to pass one place, you only have to decide the rules at that place. That is also the weakness. Anything that does not pass through the choke point is not covered, and the second half of this page is about those gaps.
Mechanism
A network firewall gives controlled access at the network level. It is installed where a protected subnetwork connects to a less trusted network. Unless a question says otherwise, assume the firewall sits between the Internet and the local network.
The ports that connect the firewall to each network are its interfaces. The default naming is the
Internet interface for the port facing the Internet and the LAN interface for the port facing the local
network. Later rule tables use inet and lan for these.
Do not confuse this with a host-based firewall. The lecture stresses that difference with its own slide: a network firewall guards a whole subnetwork from the boundary, and a host-based firewall runs on one machine.
Mechanism
Incoming and outgoing depend on where you stand when you look at the packet.
- LAN administrator’s view. Incoming is from the Internet to the local network. Outgoing is from the local network to the Internet.
- Firewall documentation’s view (the man page). Look from inside the firewall. On each interface there are incoming packets, those entering the firewall through that interface, and outgoing packets, those leaving through it. A packet that crosses the firewall is incoming on one interface and outgoing on another.
The two views give opposite answers for the same packet in some cases. A reply from the Internet to a LAN
host is incoming for the administrator. For the firewall documentation it is incoming on the inet
interface and then outgoing on the lan interface.
Compare
Incoming means Internet to local network. Outgoing means local network to Internet. One direction each, defined by the boundary of the protected network.
Incoming means entering the firewall through any interface. Outgoing means leaving the firewall through any interface. Every interface has both.
Pitfall
Do not answer a question about direction until you know whose viewpoint it uses. A packet that is incoming for the LAN administrator can be outgoing on one of the firewall’s own interfaces.
Threat
An attacker who is already inside, or who reaches the network over a path the firewall does not see, never has to get past the rules. Each limitation below is a version of this: the firewall can only judge traffic that crosses it.
Exam detail
The lecture lists what a firewall cannot do. Learn the list and the reason behind each item.
- Malicious insiders. The attacker is already on the protected side.
- Connections that do not go through it. A route around the firewall is not filtered at all.
- Completely new threats. Rules describe what the administrator already knows to allow or deny.
- Viruses, fully. If viruses spread through email and the email service is allowed through, which is typically the case, the firewall passes them.
- Cryptographic operations. A firewall does not authenticate messages. It is often co-located with VPN endpoints, and the VPN does the cryptography.
- Setting itself up correctly. Someone has to write the rules, and a wrong rule is a hole.
The lecture adds that firewalls work at specific layers of the protocol stack, so they can miss threats at higher layers such as email-based attacks and data-driven exploits in message headers, and that filtering at higher layers adds complexity and lowers processing speed. It also names human problems a firewall cannot solve, such as non-cooperation and transitive trust, where an indirect relationship between trusted networks brings in risk. Firewall software can also contain errors. A firewall used badly gives a false sense of security.
Aside
The last page of this module covers the setups built to limit the damage when one firewall is compromised, such as a DMZ with two firewalls.
Recall
A company allows email through its firewall. Name two limitations of the firewall that this one decision already exposes.
A virus carried by email passes, because the firewall allows the email service. A malicious insider can also send data out by email, because the traffic starts inside and leaves on a permitted service. Both are on the lecture’s list of things a firewall cannot stop.
Recall
- A network firewall sits where a protected subnetwork meets a less trusted network, by default between the Internet and the LAN, and is not the same thing as a host-based firewall.
- Incoming and outgoing change with the viewpoint. The LAN administrator’s view is by network boundary, the firewall documentation’s view is by interface.
- A firewall cannot stop malicious insiders, connections that bypass it, completely new threats, or viruses on an allowed service.
- It does no cryptography, and it cannot set itself up correctly.
Source
Week 9 slides PDF