TechKnowSurge
ISC2 CC 4.1 ISC2 CC 4.2 NIST 800-53 SC-7 CompTIA Network+ 4.3 CompTIA Network+ 1.2 CompTIA Security+ 3.2 Cisco CCST Cybersecurity 2.3
InteractiveSecurityFree

Allowed or Blocked?

A connection reaches the firewall. Does it get through, and why? Read the zones and rules, then predict.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

A firewall sits between the internal network and the rest of the world and decides, for traffic in each direction, whether to allow or deny it. Security zones. The firewall's interfaces are grouped into zones by trust: the internet (least trusted), the screened subnet or DMZ (more trusted), and the internal network (most trusted). A common policy, the one in this activity, lets a connection start from a more trusted zone toward a less trusted one, and blocks anything starting the other way unless a condition is met. Returning traffic. When a machine inside asks a website for a page, the firewall records the outgoing connection and lets the matching reply back in. This is stateful inspection: the firewall keeps a table of the connections it has seen start, and a packet that claims to be a reply but matches nothing in that table is dropped. ACL rules. An access control list creates exceptions: "allow the internet to reach the web server on port 443". A rule can match on MAC or IP address, protocol and port, and on some firewalls a URL. An ACL can also deny: a rule can block an address that the zone policy would otherwise allow. Next-generation firewalls. A traditional firewall decides on header information: addresses, protocol and port number. A port only suggests an application (443 is usually web traffic), so a traditional firewall cannot tell what really travels on an allowed port. A next-generation firewall (NGFW) uses deep packet inspection to identify the application and look into the content, for example to recognize malware in a download. To see inside encrypted HTTPS, it has to decrypt it (TLS inspection) where the organization has set that up. The video places traditional firewalls at OSI layers 1 to 4; the information they filter on is in the layer 2 to 4 headers (MAC, IP, port). Layer 1 is the signal itself, and nothing filters on it.

What you'll learn

Aligned to

ISC2 CC
4.1 Understand network security
4.2 Understand network security architecture
NIST 800-53
SC-7 Boundary Protection
CompTIA Network+
4.3 Given a scenario, apply network security features, defense techniques, and solutions.
1.2 Compare and contrast networking appliances, applications, and functions.
CompTIA Security+
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
Cisco CCST Cybersecurity
2.3 Describe network infrastructure and technologies

Key terms

Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Security Zone
A logical grouping of network interfaces or segments within a firewall that share the same security policies and trust level.
Screened Subnet
A dedicated network segment that hosts publicly accessible services, isolating them from the internal network so that a compromised host cannot directly access internal resources.
Stateful Packet Inspection
SPI
A firewall method that tracks the state of active connections and uses that context to determine whether inbound packets belong to a legitimate outbound session.
Access Control List
ACL
A set of rules that defines which users or systems are granted or denied access to a resource.
Packet Filtering
A firewall technique that inspects packets and allows or blocks them based on source, destination, and protocol.
Next-Generation Firewall
NGFW
A Next-Generation Firewall is an advanced network security device that combines traditional stateful packet inspection with application awareness, deep packet inspection, intrusion prevention, and threat intelligence to control traffic at Layer 7.
Deep Packet Inspection
DPI
Deep Packet Inspection is a network traffic analysis technique that examines packet payloads beyond the header layer, enabling content-aware filtering, intrusion detection, and application identification.

Topics

Firewall Security Zone Next Generation Firewall Interactive Predict

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →