4.1 KiB
Firewall – Basics
What a firewall does, how packet filtering works, and the relationship between ports and rules.
For generic networking concepts, see:
Scope
- What a firewall is and why it matters.
- Stateless vs stateful filtering.
- Inbound vs outbound rules.
- How ports relate to firewall rules.
- Linux firewall tooling.
1. What Is a Firewall?
A firewall is a system that controls which network traffic is allowed to pass, based on a set of rules. It can run on a dedicated appliance, a router, or directly on the host OS.
Rules are evaluated against packet attributes:
- Source and destination IP address.
- Source and destination port.
- Protocol (TCP or UDP).
- Connection state.
Traffic that does not match any allow rule is typically dropped (silently discarded) or rejected (a "connection refused" response is sent back).
2. Stateless vs Stateful Filtering
2.1 Stateless
Each packet is evaluated independently. The firewall has no memory of previous packets.
Simple and fast, but incomplete: to allow a TCP connection, you would need to explicitly create rules in both directions, since the response packets are separate.
2.2 Stateful (Connection Tracking)
The firewall tracks the state of each connection. It knows whether a packet is:
- NEW — initiating a new connection.
- ESTABLISHED — part of an already-allowed connection.
- RELATED — related to an existing connection (for example an FTP data channel).
This makes rules much simpler: allow NEW connections matching certain criteria, and the return traffic (ESTABLISHED/RELATED) is automatically let through. Most modern host firewalls are stateful, including Linux nftables and iptables.
3. Inbound vs Outbound Rules
- Inbound (ingress) — traffic arriving at the machine from outside. This is where most filtering happens: blocking access to ports that should not be public.
- Outbound (egress) — traffic leaving the machine. Often unrestricted on home or personal servers, but can be tightened in high-security environments.
4. Ports and Firewall Rules
"Opening a port" means adding an inbound rule to allow traffic on that port number to reach the service listening on it.
Example rule set:
| Action | Protocol | Port | Source | Effect |
|---|---|---|---|---|
| ALLOW | TCP | 443 | any | Anyone can reach the HTTPS reverse proxy |
| ALLOW | TCP | 80 | any | HTTP (redirect to HTTPS) |
| ALLOW | TCP | 22 | 192.168.1.0/24 | SSH only from the local network |
| ALLOW | UDP | 51820 | any | WireGuard peers can connect |
| DROP | TCP | 5432 | any | PostgreSQL is not accessible externally |
Good practice: only allow ports that are actively needed. Every exposed port is a potential attack surface.
5. Linux Firewall Tooling
Linux manages packet filtering through Netfilter, a subsystem built into the kernel. Several tools provide a user-space interface to it:
| Tool | Description |
|---|---|
iptables |
The classic interface to Netfilter. Still widely used, but being replaced by nftables. |
nftables |
The modern replacement for iptables. Cleaner syntax, better performance. |
ufw |
"Uncomplicated Firewall" — a simplified front-end for iptables. Good for basic setups. |
firewalld |
Dynamic firewall manager used on RHEL/Fedora systems. |
On Debian, ufw or direct nftables rules are the most common choices.
Notes / TODO
- Document the actual firewall rules in use on the home server (ports 80, 443, 22, 51820).
- Create
Home-Server/Implementations/Firewall.mdonce the setup is confirmed.