Firewall Basics: Packet Filtering, Stateful Inspection and WAF

Difficulty: Intermediate

Question

What is a firewall and what types exist? Explain stateless versus stateful filtering, DMZ, and how a WAF differs from a network firewall.

Answer

A firewall is a gatekeeper that decides which network traffic is allowed to pass between zones of different trust, based on a set of rules. Think of the security desk at a residential society: it checks who is coming, for which flat, and whether the resident expects them. The general principle is default deny: block everything, then explicitly allow what is needed.

The simplest kind is a packet filtering firewall, working at layers 3 and 4. It examines each packet in isolation against rules like allow TCP from any source to 10.0.1.5 port 443, deny everything else. Rules match on source and destination IP, protocol, ports and sometimes interface. Access Control Lists (ACLs) on routers are an example. This approach is fast and stateless: it has no memory of earlier packets. That creates trouble for return traffic. If you allow outbound web browsing you also need a rule to allow the inbound replies, and to do that safely you would need to open a large range of high ports, which is dangerous.

A stateful inspection firewall solves this by tracking connections in a state table. When your laptop opens a connection to a server, the firewall records the 5-tuple and the connection state (SYN sent, established, and so on). Replies belonging to an established connection are automatically allowed, while unsolicited inbound packets that match no entry are dropped. Modern security groups in AWS are stateful, whereas network ACLs in AWS are stateless, which is a favourite cloud interview follow-up. Stateful firewalls also understand protocol behaviour, such as opening a temporary pinhole for FTP data connections.

Next generation firewalls (NGFW) add application awareness (identifying apps regardless of port, such as Skype or BitTorrent on port 443), deep packet inspection, intrusion prevention (IPS) signatures, TLS inspection, user identity and threat intelligence feeds. Application-layer or proxy firewalls terminate the connection and re-originate it, inspecting full content.

A WAF, Web Application Firewall, is a layer 7 firewall specialised for HTTP. A network firewall would happily allow a request to port 443 of your web server, since that port is permitted, but it cannot tell that the request contains SQL injection in a query string or an XSS payload in a form field. A WAF parses HTTP and blocks these using rule sets like the OWASP Core Rule Set, and adds rate limiting and bot detection. Examples: AWS WAF, Cloudflare WAF, ModSecurity. It complements, not replaces, secure coding.

Deployment patterns: perimeter firewalls between the internet and the internal network; a DMZ (demilitarised zone), a separate network segment that holds public-facing servers such as web and mail servers, with the internet allowed to reach the DMZ, the DMZ allowed limited access to the internal network, and the internal network never directly reachable from outside, so a compromised web server cannot roam freely. Host-based firewalls (iptables, nftables, Windows Defender Firewall) protect individual machines, and microsegmentation applies the same idea between workloads inside a data centre. Firewalls cannot stop everything: they do not defend against insiders, encrypted malware they cannot inspect, phishing that persuades a user to download something, or attacks inside allowed traffic. That is why we talk about defence in depth.

Code examples

Simple stateful iptables policy

iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --dport 22  -s 203.0.113.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-request -m limit --limit 5/s -j ACCEPT

Default deny, allow replies to established connections via conntrack, SSH only from an office subnet, HTTPS from anywhere, and rate-limited ping.

Key points

Concepts covered

Firewall, Packet Filtering, Stateful Inspection, ACL, DMZ