Rule tables, first match and default policy
How a firewall rule is built from a match condition and an action, why the list is read top to bottom until one rule matches, and the difference between whitelisting and blacklisting.
- Describe a firewall rule as a match condition plus an action, and name the actions the lecture lists.
- Explain that the ruleset is processed sequentially until the first matching rule.
- Distinguish whitelisting from blacklisting and say which one the lecture recommends.
- Read the lecture's outgoing-HTTP rule table and say what each rule permits.
15 min read
Intuition
A firewall has no judgement. It has a list. For each packet it starts at the top of the list, finds the first entry that describes the packet, and does what that entry says. Everything about firewall design is therefore about what to write on the list, and in what order.
The other decision is what happens to a packet that nobody described. Either the answer is no, and every permitted thing must be written down, or the answer is yes, and every forbidden thing must be.
Mechanism
A firewall is configured by a list of rules. For every packet, the ruleset is processed sequentially until a matching rule is found. A rule has two parts: a match condition and an action.
Actions the lecture names:
- Accept permits the traffic through.
- Drop blocks the traffic with no reply.
- Reject blocks the traffic and replies with an unreachable error.
- Log records details about the traffic and does not affect its flow.
Match conditions can use the incoming interface, packet fields at different layers, stateful matches where the firewall tracks connections for you, and further conditions such as rate limits.
Mechanism
The packet fields a rule can match on, by layer:
| Layer | Fields | Note from the lecture |
|---|---|---|
| Link (L2, Ethernet) | MAC address | Easily spoofable |
| Network (L3, IPv4) | IP addresses, transport protocol (TCP, UDP, ICMP) | |
| Transport (L4, TCP/UDP) | Ports, flags | Ports identify the sending or receiving application |
Ports fall into ranges. Well-known ports are 0 to 1023, for example HTTP on 80, DNS on 53 and HTTPS on
443. Registered ports are 1024 to 49151, for example IRC on 6667 and a BitTorrent tracker on 6969.
Ephemeral ports are 49152 to 65535.
Three TCP flags matter for filtering. ACK is set in every segment of a connection except the first. SYN is
only set in the first two segments. RST is an ungraceful close of the connection.
A * in a rule field is a wildcard: the field can hold any value and it does not affect whether the rule
applies.
Compare
Everything not explicitly permitted is denied. Increased security. The lecture names it best practice, while noting it may not be practical in many situations. The list needs constant updating as new legitimate entities appear, which is expensive in large or changing environments.
Everything not explicitly forbidden is permitted. Less hassle with users, because nothing legitimate is blocked by an omission. The cost is that any threat nobody thought to list gets through.
Mechanism
The lecture’s worked configuration implements the policy allow outgoing HTTP (TCP port 80), deny the rest
on a LAN of 192.168.0.0/16. It is a whitelist, and its last rule is the default deny.
| Rule | Interface | Source IP | Destination IP | Protocol | Source port | Destination port | State | Action |
|---|---|---|---|---|---|---|---|---|
| A | lan | 192.168.0.0/16 | 0.0.0.0/0 | TCP | > 1023 | 80 | New, Est. | Accept |
| B | inet | 0.0.0.0/0 | 192.168.0.0/16 | TCP | 80 | > 1023 | Est. | Accept |
| C | * | 0.0.0.0/0 | 0.0.0.0/0 | * | * | * | * | Drop |
Each rule exists for one piece of the policy.
- The LAN can initiate outgoing HTTP connections. Rule A with state New covers the first packet, for example
a
SYN. - The Internet may respond on established connections. Rule B covers the reply, for example
SYN,ACK. - The LAN may keep using established connections. Rule A with state Est. covers the later packets, for
example
ACKandHTTP GET / HTTP/1.0. - Everything else is prohibited. Rule C drops it. A DNS lookup is the lecture’s example of what this blocks.
Pitfall
Rule B in the lecture’s table is only correct for replies. Its source port is 80 and its destination port is
above 1023, which is a server answering a client. Swapping those fields gives a rule that admits traffic the
policy never allowed. When you read a rule table, say in words who is sending, to whom, and on which side of the
firewall the packet arrived.
Exam detail
Know four things cold. A rule is a match condition plus an action. The ruleset is processed sequentially and stops at the first match. Whitelisting is default deny and is the best practice, while blacklisting is default permit. The usual way to get whitelisting in a rule table is a final rule that matches everything and drops.
For any rule table, translate each row into a sentence about the policy it serves before judging the table. The practice-quiz questions that give you a table ask you to say what a rule permits and whether an earlier rule makes a later one unreachable.
Aside
The slide table for this example shows rule A’s state as New, Est. and rule B’s as Est., which is what the
page reproduces. The accompanying text also says the replies on rule B carry SYN and/or ACK, which is how
the firewall recognises them as part of a connection already started from inside.
Recall
In the outgoing-HTTP table, a packet from a LAN host to port 53 on an outside server arrives on the `lan` interface. Which rule decides what happens to it, and what is the action?
Rule A does not match, because its destination port is 80. Rule B does not match, because it applies to the
inet interface. Rule C matches everything, so it decides, and the action is Drop. The lecture uses a DNS
lookup as its example of traffic this policy prohibits.
Recall
- A rule is a match condition plus an action. The actions are Accept, Drop, Reject and Log.
- Rules are read in order and the first match wins.
- Whitelisting is default deny and is the lecture’s best practice. Blacklisting is default permit.
- A MAC address is easily spoofed. Well-known ports are 0 to 1023, registered 1024 to 49151, ephemeral 49152 to 65535.
Source
Week 9 slides PDF