# Firewalls - A hardware and/or software system - Prevents unauthorised access of packets from one network to another - All data leave any subnet must pass through it ![1647287782.png](img/1647287782.png) ### Firewall Functions - Implements *single point* security measures - Security event monitoring through packet analysis and *logging* - Network-based access control through implementation of a rules set **Network Firewalls** - placed between a subnet and the internet **Host-based Firewalls** - placed on individual machines - A standard home router is a good example of a network firewall ![1647288145.png](img/1647288145.png) #### DMZ - A demilitarised zone is a small subnet that separates exrternally facing services from the internal network ![1647288286.png](img/1647288286.png) - Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network ##### Basic Function - Defends a network against parties accessing *internal services* - Can also restrict access from *inside to outside* services - Network Address Translation - Hides the internal machines with private addresses **Firewalls are not enough** - Cannot protect against attacks that bypass the firewall - e.g. tunneling - Cannot protect against internal threats or insiders - Might help a bit by egress filtering - Network firewalls cannot always protect against the transfer of virus-infected programs or files #### Packet Filters - Specify which packets are *allowed or dropped* - Rules based on: - Source / destination IP - TCP / UDP port numbers - Possible for both *inbound* and *outbound* traffic - Can be implemented in a router by only examining packet headers (**IP / TCP**) ##### Packet Filter Rules - Rule execution depends on implementation - `IPTABLES`: **First** rule to match is applied - `PF`: All rules are examined, **last** match is applied - Rules are organised in *chains*, which are logical subgroups of rules - Depending on the packet, different chains are activated ###### IPTABLES - An application that provides access to the Linux firewall rule tables - Not actually a firewall, but configures the firewall - The firewall is mostly implemented as `netfilter` modules ###### Tables and Chains - `IPTABLES` uses tables to store chains - Default is the filtering table - Chains are ordered in lists of rules - Rules match, or they don’t - Matches result in a **jump**, else we check the next rule. ![1647289401.png](img/1647289401.png) Default policy on this chain is `DROP` - There can be multiple chains per table - e.g. a `TCP` handling chain - Jumps can go to `ACCEPT`, `DROP`, `LOG` or another chain - Complex behaviour can be built up ![1647289523.png](img/1647289523.png) ##### Defaults - There are four built-in tables in `IPTABLES` - Filter - `NAT` - Mangle - packet alteration - Raw - skips connection tracking - The default table is the filtering table, including input, output and forward chains ![1647289692.png](img/1647289692.png) ###### Rules Examples - Using the command line, we add rules onto the end of chains ```bash $ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT $ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT ``` - Remember `http` requests are not sent from the client’s port 80, it is sent from a random high numbered port - This is how clients can have multiple web requests open at the same time ##### Policies - **Permissive** - allow everything by default except dangerous services - Make a black list - Easy to make a mistake or forget something ```bash iptables -p INPUT ACCEPT iptables -p FORWARD ACCEPT iptables -p OUTPUT ACCEPT iptables -A INPUT -s X.X.X.X -j DROP iptables -A OUTPUT -p tcp --dport ssh -j DROP ``` - **Restrictive** - block everything except designated useful services - Make a white list - More secure by default ```bash iptables -p INPUT DROP iptables -p FORWARD DROP iptables -p OUTPUT DROP iptables -A INPUT -p tcp --dport ssh -j ACCEPT iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT ``` #### Packet Filter Issues - Packet filters are simple, low-level and have high assurance - However they cannot: - Prevent attacks that employ application specific vulnerabilities - Do not support higher-level authentication schemes - Easy to accidentally allow or deny packets incorrectly ### Stateful Packet Filters - Understand requests and replies (`ACK/SYN`) - Dynamically generate rules - Based on what it sees from TCP handshakes (can be FTP or SSH etc) - Can support policies for a wider range or protocols - `IPTABLES` has a module for stateful packet filtering - Allow incoming / outgoing SSH connections ![1647290573.png](img/1647290573.png) #### Connection Tables ![1647290603.png](img/1647290603.png) - `ACK` packets are used to keep track of the session - the connection is ongoing - Packets without the `ACK` are the connection establishment messages #### Application-level Gateways - Packet filters have limited criteria that allow data in and out - An application gateway considers the *application-layer* protocol that is in use - For example if someone sends an `HTTP` request to port 22, it is blocked ##### Proxy Server - Proxy servers initiate a connection on our behalf - They can block certain access, and scan for malicious files or web pages ![1647290781.png](img/1647290781.png) **Issues**: - Large overhead per connection - More expensive than packet filtering - Configuration is complex - A separate server is required for each service ### Network Address Translation The shortage of IP addresses mean that most routers now perform NAT automatically ![1647290897.png](img/1647290897.png) - The implicit advantage in NAT is that your machine is almost totally hidden from the internet - Only **established connections** are forwarded to your internal machine - Or, specific **port forwarding** rules - This prevents any unsolicited attacks on random ports, but no other types of attack