Spoofing protection and rule shadowing
The source-address rules a firewall applies to stop IP spoofing in both directions, the lecture's spoofing-protection table, the common configuration mistakes, and how an earlier rule can shadow a later one.
- Explain what IP spoofing is and why a network should filter its outgoing traffic as well as its incoming traffic.
- Read the lecture's spoofing-protection table and say what each rule drops.
- Define shadowing and identify which rule is shadowed in a pair of rules.
- List the common firewall mistakes the lecture names.
15 min read
Intuition
A packet’s source address is just a field that the sender writes. Nothing in IP checks that it is true. A firewall at the boundary of a network is in a good position to notice lies of one particular kind, because it knows which addresses should appear on which side. A packet on the Internet side claiming to come from inside has to be forged.
A second problem is not an attack at all. It is the administrator writing rules that quietly cancel each other. Both are about how a rule list behaves, and both are cheap to check once you know to look.
Threat
IP spoofing is when an attacker falsifies the source IP address in packets, so they appear to come from a trusted or legitimate source. It is commonly used in DDoS attacks and to bypass security controls that trust the source address.
Control
Spoofing protection is a firewall measure that validates source IP addresses, to stop spoofed traffic entering or leaving a network. It cannot tell a truthful public address from a forged one that happens to be plausible. It removes the addresses that cannot be true on a given interface.
Mechanism
The lecture applies the check in both directions.
- Outgoing, to the Internet. Only allow source IPs that belong to you. The lecture’s reason: do not be an operator who facilitates spoofed DoS attacks on the Internet.
- Incoming, from the Internet. Only allow valid source IPs, for a varying definition of valid. IPs that belong to you are not valid. Local and special-purpose IPs are not valid.
The lecture’s table assumes the institution owns 129.78.0.0/16 and also wants to drop private-address
traffic.
| Rule | Interface | Source IP | Destination IP | Action |
|---|---|---|---|---|
| A | lan | !129.78.0.0/16 | * | Drop |
| B | inet | 129.78.0.0/16 | * | Drop |
| C | inet | 192.168.0.0/16 | * | Drop |
| D | inet | 10.0.0.0/8 | * | Drop |
| E | inet | 172.16.0.0/12 | * | Drop |
| F | * | * | * | Accept |
- A is the outgoing check. On the
laninterface, a source that is not in your own range is dropped. - B is the incoming check for your own addresses. On the
inetinterface, a source inside your range is dropped. - C, D and E drop the three private ranges when they arrive from the Internet.
- F accepts everything the earlier rules did not drop.
Worked example
Answer1 is accepted by F, 2 is dropped by A, 3 is dropped by B, 4 is dropped by D.
- Packet 1 arrives on
lanwith source129.78.5.1, which is inside129.78.0.0/16. Rule A drops sources that are not in that range, so it does not match. B, C, D and E needinet. F matches. Accepted. This is a legitimate outgoing packet. - Packet 2 arrives on
lanwith source8.8.8.8. That is not inside129.78.0.0/16, so rule A matches. Dropped. - Packet 3 arrives on
inetwith source129.78.5.1. Rule A needslan. Rule B matches, since a packet from outside must not carry one of your addresses. Dropped. - Packet 4 arrives on
inetwith source10.1.1.1. Rules A and B do not match. Rule C needs192.168.0.0/16, so no. Rule D matches10.0.0.0/8. Dropped.
Mechanism
The lecture then lists mistakes to check for in a real configuration.
- How is the firewall management interface reachable? From the Internet, or from the complete internal network?
- What is allowed over the Internet?
- Do you use IPv4 and IPv6, and are the rules the same?
- Is there an outbound rule of ANY? The lecture ties this to spoofing.
Mechanism
Shadowing is when all the packets one rule intends to deny, or accept, have already been accepted, or denied, by preceding rules. Because rules are matched sequentially, a shadowed rule never matches.
| Rule | Interface | Source IP | Destination IP | Action |
|---|---|---|---|---|
| A | * | * | 192.168.0.0/16 | Accept |
| B | * | * | 192.168.42.0/24 | Drop |
Rule B is meant to drop traffic to 192.168.42.0/24. That range is inside 192.168.0.0/16, so rule A has
already accepted every packet rule B would have matched. Rule B can never take effect.
Pitfall
Shadowing is not about which rule is more specific. A specific rule placed after a general one that covers it is shadowed, because order decides. The reverse order, the specific Drop first and the general Accept after, makes both rules work. In an exam table, check each rule against every rule above it, not only against the rule directly above.
Exam detail
The lecture’s practice quiz uses a rule table to ask which rule shadows which, and you have to read the rules against the ones before them. The definition to write is the one on this page: the packets a rule is meant to deny or accept are already handled by earlier rules. One of the practice questions has one rule allowing outgoing connections using any protocol, which makes a later rule for blocking a specific service unreachable, so employees can still use it.
The figures for that quiz are not in the extracted material. Practise the method above on the table from the slides, and use the lecture recording or the original practice quiz for the exact rules.
Aside
The lecture’s own text lists loopback addresses as special-purpose addresses that should be invalid as a source from the Internet. The table in the slides has no rule for them, and the page does not add one.
Recall
A packet arrives on the `inet` interface with source 192.168.7.7. Which rule in the spoofing table decides, and what is the action?
Rule A needs lan and rule B needs a source in 129.78.0.0/16, so neither matches. Rule C matches the source
192.168.0.0/16 on inet. It is the first match, so it decides, and the action is Drop.
Recall
- Spoofing protection filters source addresses both ways. Outgoing, only your own addresses may leave. Incoming, your own addresses and private and special-purpose ones are invalid.
- The lecture’s table drops
!129.78.0.0/16onlan, and129.78.0.0/16,192.168.0.0/16,10.0.0.0/8and172.16.0.0/12oninet, then accepts everything else. - Shadowing means an earlier rule already handles the packets a later rule was meant to. The later rule never matches.
- Common mistakes include a reachable management interface, different IPv4 and IPv6 rules, and an outbound rule of ANY.
Source
Week 9 slides PDF