Firewalls and its Types in Network Security

1
0

Introduction

A firewall is a security system that controls network traffic based on predefined rules. It works like a gatekeeper between trusted and untrusted networks, deciding which traffic should be allowed and which traffic should be blocked.

The core idea behind a firewall is simple: every device or service should not be reachable by everyone. A database server, internal admin panel, or private application should not be openly accessible from the public internet unless there is a clear reason.

What Does a Firewall Do?

A firewall checks incoming and outgoing traffic and applies security rules to it. These rules define which communication is trusted, which communication is risky, and which communication should never be allowed.

A firewall can perform actions such as:

  • Allow: Permits trusted traffic to pass through.

  • Block: Drops unauthorized or suspicious traffic.

  • Reject: Blocks the traffic and sends a response back to the sender.

  • Log: Records traffic details for monitoring and auditing.

  • Rate limit: Restricts excessive traffic from the same source.

  • Inspect: Performs deeper checks before allowing traffic.

A firewall reduces the attack surface of a network. It does not fix insecure applications, but it limits who can reach those applications and services.

What Can a Firewall Inspect?

Different firewall types inspect different parts of network traffic. Basic firewalls look mainly at network-level details, while advanced firewalls can inspect application-level behavior.

Common inspection points include:

  • Source IP address: Where the traffic is coming from.

  • Destination IP address: Which system the traffic is trying to reach.

  • Port number: Which service is being accessed, such as port 443 for HTTPS.

  • Protocol: Whether the traffic uses TCP, UDP, ICMP, or another protocol.

  • Connection state: Whether the packet belongs to a valid ongoing session.

  • Application data: HTTP paths, headers, request body, cookies, or suspicious payloads.

This is why all firewalls are not equal. A simple packet filtering firewall may only check IPs and ports, while a web application firewall can detect attacks hidden inside HTTP requests.

Firewalls and Types

Firewalls and Types

Why Firewalls Are Needed

Without a firewall, a network can become unnecessarily exposed. Any open service may be discovered, scanned, or attacked by unauthorized users.

Firewalls are needed because they help:

  • Prevent unauthorized access: Only approved traffic is allowed into protected systems.

  • Protect sensitive services: Databases, internal tools, and admin ports can be hidden from public access.

  • Control network boundaries: Traffic between the internet, internal networks, cloud systems, and servers can be filtered.

  • Reduce attack surface: Fewer exposed services means fewer entry points for attackers.

  • Support monitoring: Firewall logs help identify suspicious access attempts and unusual traffic patterns.

For example, a public web server may allow HTTPS traffic on port 443 but block direct access to MySQL on port 3306. Users can reach the website, but they cannot directly connect to the database.

Packet Filtering Firewall

A packet filtering firewall is one of the simplest firewall types. It checks each packet independently and decides whether to allow or block it based on header information.

It usually checks details such as source IP, destination IP, port number, protocol, and traffic direction. Since it does not remember previous packets, it is also called a stateless firewall.

  • Fast and lightweight: It performs basic checks with low processing overhead.

  • Simple rule-based filtering: It allows or blocks traffic using predefined rules.

  • Limited context: It cannot understand whether a packet belongs to a valid conversation.

  • No deep inspection: It cannot detect application-layer attacks such as SQL injection or XSS.

Packet filtering is useful for basic access control, but it is not enough as the only defense in modern networks.

Stateful Inspection Firewall

A stateful inspection firewall is smarter than a packet filtering firewall because it tracks active connections. Instead of checking every packet in isolation, it maintains a state table that records valid sessions.

For example, when an internal user opens a website, the firewall remembers that connection. When the server sends a response back, the firewall allows it because it belongs to an already established session.

A simple TCP connection flow looks like:

Client sends SYN => Server replies SYN-ACK => Client sends ACK => Data transfer begins

A stateful firewall understands this flow and can block packets that do not match any valid connection.

  • Connection awareness: It tracks whether traffic belongs to a new, established, or closing session.

  • Better security: It blocks unexpected packets that do not fit a known connection.

  • Simpler rules: Return traffic can be allowed automatically for valid sessions.

  • Higher resource usage: Maintaining state tables requires more memory and processing power.

Stateful inspection firewalls are widely used because they provide a strong balance between security and performance.

Web Application Firewall

A Web Application Firewall, or WAF, protects web applications by inspecting HTTP and HTTPS traffic. Unlike traditional firewalls that focus on IP addresses, ports, and protocols, a WAF looks at application-layer details.

A WAF can inspect URL paths, query parameters, headers, cookies, request bodies, HTTP methods, and suspicious payload patterns. This makes it useful for protecting websites, APIs, login pages, dashboards, and backend applications.

A WAF can help detect and block attacks such as:

  • SQL injection: Malicious SQL input designed to manipulate database queries.

  • Cross-site scripting: Script injection attempts that target users through web pages.

  • Path traversal: Attempts to access restricted files or directories.

  • Brute force attempts: Repeated login attempts against user accounts.

  • Malicious bots: Automated traffic used for scraping, scanning, or abuse.

For example, if an attacker sends a search request containing a suspicious SQL pattern, a WAF may block the request before it reaches the application server.

Firewall vs WAF

Aspect

Traditional Firewall

Web Application Firewall

Main focus

Network access control

Web application protection

Common layers

Layer 3 and Layer 4

Layer 7

Inspects

IP addresses, ports, protocols, connection state

HTTP requests, headers, cookies, URL paths, request body

Protects against

Unauthorized access and unwanted network traffic

SQL injection, XSS, malicious payloads, web attacks

Common placement

Network edge, cloud VPC, internal network segment

In front of web apps, APIs, or behind CDN/reverse proxy

A traditional firewall protects network doors. A WAF protects application doors. In real systems, both are often used together.

Summary

A firewall is a key part of network security because it controls which traffic can enter, leave, or move inside a network. It uses rules based on IP addresses, ports, protocols, connection state, and sometimes application data to allow trusted traffic and block risky traffic.

Packet filtering firewalls provide basic stateless filtering, stateful inspection firewalls track active connections, and web application firewalls protect websites and APIs from application-layer attacks. Modern networks often combine multiple firewall types to reduce exposure, protect sensitive systems, and build stronger layered security.

CS Core

Read Similar Blogs

Comments0