Skip to Content
Security Power Tools
book

Security Power Tools

by Bryan Burns, Dave Killion, Nicolas Beauchesne, Eric Moret, Julien Sobrier, Michael Lynn, Eric Markham, Chris Iezzoni, Philippe Biondi, Jennifer Stisa Granick, Steve Manzuik, Paul Guersch
August 2007
Intermediate to advanced
856 pages
25h 19m
English
O'Reilly Media, Inc.
Content preview from Security Power Tools

Chapter 13. Proactive Defense: Firewalls

Most people have at best a fuzzy idea of just what a firewall is and how it really works. Thanks to Hollywood and the many Mission Impossible-like movies, quite a few think it has something to do with disassembling a fax machine and hooking it to an iPod.

In its most pure state, a firewall is actually a very straightforward and simple thing. A firewall inspects packets as they arrive on an interface, searching a table until it finds a matching rule to determine what it should do with each packet, and then follows the action the rule specifies.

If the packet does not match a specific rule, a default action decides the packet’s fate, generally known as falling through the bottom of the rules. For firewalls, the generally accepted good default action is Deny. That is, unless we explicitly permit a particular access, the packet is dropped. This allows us to permit what we know and block what we do not.

Firewall Basics

Generally there are three ways to deploy a firewall: as a Router/NAT Gateway, on an endpoint as a Host-based Firewall, or as a Transparent/Bridging firewall. I will cover the first two in this chapter—the Router and the Host.

Router/Network Address Translation Router

This kind of firewall sits between different LAN subnets at Layer 3 and filters traffic sent to it for forwarding. It cannot prevent attacks between individual nodes on the same subnet (see the section "Transparent/Bridge Firewall" later in this chapter). It may perform Network ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Applied Network Security

Applied Network Security

Warun Levesque, Arthur Salmon, Michael McLafferty
Penetration Testing and Network Defense

Penetration Testing and Network Defense

Andrew Whitaker, Daniel P. Newman

Publisher Resources

ISBN: 9780596009632Errata Page