Stateful matching
How a stateful firewall tracks connections with the IP 5-tuple, the NEW and ESTABLISHED states, the lecture's mail-server rule table, and why moving the established rule to the top speeds the firewall up.
- Name the five fields of the connection-tracking tuple and the two connection states.
- Explain why UDP connection tracking is only an approximation.
- Read the lecture's stateful mail-server table and say what each rule permits.
- Explain the two tuning changes the lecture makes and why each helps.
15 min read
Intuition
Think about replies. When a LAN host contacts a web server, the web server’s answer comes back from outside. A firewall that judges each packet alone has to decide whether that answer is welcome without knowing it is an answer. A stateful firewall remembers the question. It saw the first packet go out, so it can recognise the replies as part of a conversation the inside started.
The cost is memory. The firewall has to keep a record of every active connection, and that record is what later pages weigh against the stateless alternative.
Mechanism
Arriving packets may generate state in the firewall. This is connection tracking, and it identifies a connection by the IP 5-tuple: source IP, destination IP, protocol, source port and destination port. Those five fields identify a network flow, which lets the firewall tell whether a packet belongs to a new or an existing connection.
A connection is in one of two states.
- NEW is the first packet of a connection, such as the
SYNin a TCP handshake. - ESTABLISHED is every packet that follows in a connection the firewall already recognises.
Tracking works well for connection-oriented protocols such as TCP, where the state changes are clear. For UDP it is always an approximation. UDP has no connection states of its own, so the firewall works from timing, packet flow patterns and heuristics.
Mechanism
The lecture’s stateful example is a LAN with a mail server. The policy:
- Incoming and outgoing email is the only traffic allowed into and out of the protected network. Email is SMTP,
TCP port
25. - Anyone in the internal network can send email to arbitrary mail servers on the Internet.
- Incoming email must only arrive at the mail server.
The rule table:
| Rule | Interface | Source IP | Destination IP | Protocol | Source port | Destination port | State | Action |
|---|---|---|---|---|---|---|---|---|
| A | inet | external | mailserver | TCP | * | 25 | New | Accept |
| B | lan | internal | external | TCP | * | 25 | New | Accept |
| C | * | * | * | * | * | * | Est. | Accept |
| D | * | * | * | * | * | * | Drop |
- Rule A lets a new incoming SMTP connection reach the internal mail server.
- Rule B lets an internal host start an SMTP connection to the Internet.
- Rule C accepts every established connection. Only rules A and B can create one, so only email connections ever reach the ESTABLISHED state, and only TCP ones.
- Rule D denies the rest, which is whitelisting.
Rules A and B name external, internal and the mail server instead of using * for the addresses. The lecture
gives this as protection against spoofing, which the spoofing page covers.
Worked example
Answer1 is accepted by rule A, 2 by rule C, 3 is dropped by rule D.
- Packet 1 arrives on
inetfrom an external host to the mail server, TCP, destination port25, and is the first packet of the connection, so its state is New. Rule A matches on interface, addresses, protocol, port and state. Accepted. - Packet 2 is the mail server’s reply to that external host, in a connection rule A already let start. Its state is Est. Rules A and B do not match, since neither accepts state Est. Rule C matches. Accepted.
- Packet 3 arrives on
lanfrom an internal host to an external web server on port80, state New. Rule A needs interfaceinet, so no. Rule B needs destination port25, so no. Rule C needs state Est., so no. Rule D matches everything. Dropped.
Mechanism
The lecture then tunes this ruleset. Rules are matched sequentially, so rule order has a large effect on performance. Two changes:
- Move rule C to the front. Many packets use an established connection, so they are now handled by the first rule and the rest are never evaluated.
- Set the source port to above 1023 instead of
*. Clients rarely use well-known ports, which are for services run by root, so a connection from a low source port is not expected. This is extra security.
The optimised table:
| Rule | Interface | Source IP | Destination IP | Protocol | Source port | Destination port | State | Action |
|---|---|---|---|---|---|---|---|---|
| C | * | * | * | * | * | * | Est. | Accept |
| A | inet | external | mailserver | TCP | > 1023 | 25 | New | Accept |
| B | lan | internal | external | TCP | > 1023 | 25 | New | Accept |
| D | * | * | * | * | * | * | Drop |
Pitfall
Rule C moving to the top is safe here only because the established state cannot be reached without passing through A or B first. The reordering does not weaken the policy. Do not generalise it into “put accept rules first” for rule tables where an earlier rule would match packets a later deny was meant to catch. That is shadowing, covered on the spoofing and shadowing page.
Exam detail
The lecture gives these as the stateful points to learn: the 5-tuple, the two states, UDP tracking being an approximation, and the tuning of moving the established rule to the front. The practice quiz asks which firewall types exist at the network layer, and the answer is stateful and stateless.
When a question gives you a table with a State column, it is a stateful configuration. A table with no State column that matches on SYN and ACK flags is stateless.
Aside
The slide copy of the rule table is partly scrambled in extraction. The destination IP of rule B and the layout of rule D differ between the slide and the text that goes with it. The page follows the lecture’s own description of the policy: rule B lets an internal host start a connection to an arbitrary mail server on the Internet, so its destination is the external side. Rule D is the final drop for everything else.
Recall
Why can a connection only reach the ESTABLISHED state in this table if it started as email?
Rule C accepts only packets already in state Est. A connection becomes established only after its first packet
was accepted as New, and only rules A and B accept New packets. Those two only match SMTP on port 25, so every
other kind of connection is dropped by rule D at its first packet and never becomes established.
Recall
- Connection tracking uses the 5-tuple: source IP, destination IP, protocol, source port, destination port.
- The states are NEW, the first packet, and ESTABLISHED, everything after it. UDP tracking is an approximation.
- In the mail-server table, rules A and B create connections, rule C accepts them once established, rule D drops the rest.
- Tune by moving the established rule first and setting the source port to above 1023.
Source
Week 9 slides PDF