CSEC3616Cybersecurity Engineering

    Dual-homed firewalls and bastion hosts

    The three common firewall setups in the lecture: the simple packet filter, the dual-homed host with its bastion variant, and the screened subnet with a DMZ, with what each protects and how each fails.

    • Describe the simple packet filter, dual-homed host and screened subnet architectures.
    • Explain what a bastion host is and why an application proxy filters at the application layer.
    • State the drawbacks of a single dual-homed host and how a DMZ limits the damage of a breach.
    • Explain why a stateful firewall does not remove the need for a DMZ.

    10 min read

    Intuition

    One rule table is not the only design choice. Where you put the firewall, and what else sits on its network, set how much one mistake costs you. A single firewall that is also the only gate is simple, and also a single point of failure. Each setup in the lecture adds something to deal with that.

    Mechanism

    Simple packet filter architecture. A single packet-filtering router or firewall sits between the internal network and the Internet and filters traffic on predefined rules.

    • One point of entry and exit between the Internet and the internal network. The device has two interfaces, one facing each side.
    • The simplest and cheapest setup. It decides on packet headers: IP addresses, ports and protocols. It may be stateless or stateful depending on the device.
    • A single point of failure. If it is compromised, the entire network is exposed.
    • Best for small networks, home offices and settings with limited security requirements.

    The rule sets can grow long and complex, and that can degrade network performance.

    Mechanism

    Dual-homed host architecture. A dedicated host with two network interface cards acts as a gateway between two networks. The host is part of both networks simultaneously, with one interface on the Internet and the other on the internal network. IP forwarding is disabled, so there is no direct routing between the networks and all traffic must be explicitly processed by the host.

    The lecture gives two ways to run it.

    • Basic dual-homed firewall. The host runs firewall software only, filters packets on rules, and may forward allowed packets between its interfaces.
    • Bastion host. A more secure version that acts as both firewall and application proxy. It forces all traffic through application-layer proxies. A proxy filters at the application layer, which is deeper than the network and transport layers that packet filtering uses.

    Advantages: the internal network is isolated from the external one, and the bastion host can apply granular controls, with the proxy enforcing specific access rules for different types of traffic. Best for medium-sized networks that need application-layer inspection.

    Threat

    The dual-homed host is one machine on both networks. If attackers gain control of it, they have direct access to both networks, and the internal network is exposed. The same design also makes it a bottleneck, because all traffic is processed by that single machine.

    Mechanism

    Screened subnet architecture, the DMZ. Publicly accessible servers go in an isolated network segment, the Demilitarized Zone, between two firewalls. This creates three security zones: the Internet, the DMZ and the internal network.

    • The external firewall sits between the Internet and the DMZ. It lets only specified types of traffic reach the DMZ servers.
    • The internal firewall sits between the DMZ and the internal network. It lets only authorised and necessary traffic reach internal systems.
    • The DMZ holds the bastion host (proxy) and the servers that need to be reachable from outside, such as web, mail and DNS servers.
    • It needs two firewalls, or one firewall with at least three network cards.

    The benefit is secondary protection. If the DMZ is breached, the internal network is still protected. The lecture lists it as limiting the blast radius of breaches, separating public and private resources, and allowing granular control of traffic between zones. It is the most secure of the common architectures, and the best fit for organisations that host public services while protecting sensitive internal resources.

    Control

    A DMZ is the lecture’s answer to the dual-homed host’s weakness. Public servers are the machines most likely to be attacked, so they are put where a compromise does not hand over the internal network. The control’s limit is that the internal firewall has to be configured to allow only what the DMZ servers genuinely need.

    Compare

    One host on both networks. Controls all traffic, and can proxy at the application layer. A bottleneck, and compromising it gives access to both networks. Suited to medium-sized networks.

    Two firewalls, or one with three or more cards, around a DMZ of public servers. Three zones, layered defence. A breach of the DMZ leaves the internal network protected. The most secure common setup.

    Pitfall

    A stateful firewall does not replace the DMZ. The practice question has an administrator who reasons that a stateful firewall plus strict rules by destination is enough. The unit’s answer is that it is not: stateful firewalls give no extra security here, and an attacker who gets in through the web server application can try to move on, which is exactly the move a DMZ is there to stop.

    Exam detail

    Learn each setup as architecture, characteristics, drawbacks and best-for. The recurring comparison is the dual-homed host against the DMZ. The two numbers to know are two firewalls or one with at least three network cards. The practice quiz asks which layer a proxy firewall filters at, and the answer is the application layer.

    Aside

    The slides describe the dual-homed host in two columns that extracted interleaved, and they are not fully consistent. They state that IP forwarding is disabled, and they also say the basic variant may forward allowed packets between its interfaces. The text that goes with them describes the dual-homed host as using a bastion host that is both firewall and application proxy, without splitting it into two variants. The page follows the slides for the split and uses the application-proxy description for the bastion host. Check the slide if an exam question turns on the difference.

    Recall

    Why can compromising the host in a dual-homed architecture be worse than breaching a DMZ server in a screened subnet?

    The dual-homed host is the single point of access between the two networks, so controlling it gives direct access to both. A DMZ server is only in the DMZ, and the internal firewall still stands between it and the internal network.

    Recall

    • Simple packet filter: one device, two interfaces, cheapest, and a single point of failure.
    • Dual-homed host: one machine on both networks, IP forwarding off. The bastion variant is firewall plus application proxy. Drawbacks are the bottleneck and the compromised-host risk.
    • Screened subnet: public servers in a DMZ between two firewalls, or one with at least three network cards. A breach of the DMZ leaves the internal network protected.
    • A stateful firewall does not make the DMZ unnecessary.