Firewalls serve as the critical security boundary between internal networks and the outside world, controlling which traffic is allowed in or out based on defined rules and inspection methods. This content covers firewall fundamentals, security zones, returning traffic handling, access control lists, and next-generation firewall capabilities.
Firewalls & Network Security
One of the most critical pieces on our network from a security standpoint is our firewall.
The most secure you can make your internal network is just by unplugging it from the rest of the world, by not letting it connect to the internet. There are too many threats out there, and there are some systems that actually implement security using this manner. However, most businesses, most organizations, most individuals need access to the outside world. That's how we do business nowadays, and so we need something that protects us from the rest of the world.
That's what a firewall does. It's the protection between our internal network and the rest of the world. So how does it do that? One, it blocks traffic from coming into your network. But it can't do just that, because obviously if I'm going out and asking for a web page, that web page needs to come back into the network, that data needs to come back into the network, since I requested it. For that reason, the firewall actually is the thing that makes the decision on what it's going to let out of the network and what it's going to let into the network. That's what a firewall's job is: it's the security point that allows or denies traffic inside and outside of these networks.
One of the key ways a firewall makes its decision is by the interface, and whether the traffic is coming in or out of each of these interfaces. You can think of these as security zones. In this instance right here, you really have three different security zones. You've got the internet right here, which is considered the least secure. You've got the screened subnet, or the DMZ, right here, which is considered more secure. And then you have this zone right here, which is considered the internal network, which is the most secure.
There are different ways that we can control the traffic coming in and out of these different zones, but one of the common ways that these firewalls are set up is that anything from the internal zone could go to the DMZ or the internet, anything from the DMZ could go out to the internet, but nothing from the internet could automatically be accepted to go into the DMZ or the internal network, and nothing from the DMZ could automatically be allowed into the internal network. So it allows traffic to go from a secured zone to a less secure zone, but it doesn't allow the traffic to go the other way unless specific conditions are met.
One of those specific conditions is returning traffic. If a machine goes out and asks for a website and requests resources from a web page, then this firewall would track that information going out and say, okay, I'm going to expect then a return traffic to come back in, and I'm going to allow that returning traffic to come back in. So that's one of the ways that it would make an exception to go from the internet to the internal zone.
Another way is through the use of access control lists, or ACLs. You might have an access control list that says, well, allow people from the internet to get to our web servers. So that's another exception where traffic would be allowed, because we want people to access our web servers, and that's what an ACL would allow us to do, is create rules that would allow that type of traffic.
There are several ways that an ACL could filter. It could do it off of a MAC address, it could do it off an IP address, it could do it off of applications and ports, it could do it through URL filtering, it could do it through stateful packet inspection. So when that traffic is coming through this firewall, then it can do these different rules, have these different ACLs, to have different methods to actually look at the traffic going across there and accept or deny based off of some of these criteria.
Traditional firewalls really were based off of the MAC address, the IP address, the application or the port numbers. It would do some filtering at a very, I'd say, low level. If you look at the OSI model, it's levels 1, 2, 3 and 4. So it's really just basing it off of a few pieces of information here on whether it's going to accept or deny.
The next generation firewall, or the NGFW, these are firewalls that will actually do these deeper packet inspections. They actually go in there and look at the traffic going back and forth and start recognizing if there is maybe some malware that's involved with this transaction, or if there's something else that's going on with the packets that are flowing back and forth. So the idea behind the next generation firewall is it's a firewall that can do a deeper packet inspection to figure out what's going on with the traffic that's going across it.
Firewalls are a critical part of protecting our network, and so setting up a firewall correctly is going to be really important. A next generation firewall actually gets into that packet inspection and is able to make some decisions based off of things that are found at the application level, and something that's much deeper inside the packet.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →