Packet.School
HomeLevelsSandboxPricingAbout
XP1,240
L4 · Network Devices
Level 4
5 lessons
  • 01Hub vs Switch
  • 02Router
  • 03Build Network Topology
  • 04Firewall
  • 05Level 4 Quiz
Levels/L4 · Network Devices/Lesson 04
Lesson · 04

Firewall

Firewall is a system that controls network traffic and ensures security.

Duration
2min
Level
L4
Type
Lesson
Progress
4/ 5

01What is a Firewall?

Firewall works like a "security gate":

  • Examines incoming and outgoing traffic
  • Allows or blocks based on rules
  • Prevents unauthorized access
code
Internet → [Firewall] → Internal Network
             ↓
         Rules:
         ✓ Port 80 (HTTP) - Allow
         ✓ Port 443 (HTTPS) - Allow
         ✗ Port 23 (Telnet) - Block

02Firewall Types

1. Packet Filtering Firewall

  • Simplest type
  • Looks at IP address and port number
  • Fast but basic

2. Stateful Firewall

  • Tracks connection state
  • Makes smarter decisions
  • "Is this packet part of an existing connection?"

3. Application Layer Firewall

  • Application-level control
  • Analyzes HTTP, FTP content
  • Most detailed control

4. Next-Generation Firewall (NGFW)

  • Combines all features
  • IPS, antivirus, SSL inspection
  • Modern enterprise solution

03Firewall Rules

Example Rule Table:

OrderSourceDestinationPortAction
1AnyWeb Server80, 443Allow
2Admin PCAnyAnyAllow
3AnyAny22Deny
4AnyAnyAnyDeny

Rule Logic:

  • Rules are checked in order
  • First matching rule is applied
  • Default: "Deny All"

04Software vs Hardware Firewall

FeatureSoftware FirewallHardware Firewall
Where?On computerAt network edge
ProtectionSingle deviceEntire network
ExampleWindows FirewallCisco ASA, Fortinet
CostLow/freeHigh
ManagementEasyExpertise needed

05DMZ (Demilitarized Zone)

Safe zone for servers open to the outside:

code
Internet → [Firewall] → DMZ → [Firewall] → Internal Network
                         ↓
                    Web Server
                    Mail Server
  • Servers in DMZ are accessible from internet
  • But they can't access internal network
  • If attacked, internal network is protected

06Summary

  • Firewall = Network security gate
  • Filters incoming/outgoing traffic
  • Rules applied in order
  • DMZ isolates external servers
Previous
Build Network Topology
Next
Level 4 Quiz
On this page
  • What is a Firewall?
  • Firewall Types
  • Firewall Rules
  • Software vs Hardware Firewall
  • DMZ (Demilitarized Zone)
  • Summary
Packet.School

An open, interactive curriculum for computer networking.

v3.0 · MIT22 lessons live

Learn

  • Lessons
  • Sandbox
  • Levels
  • Pricing
  • About

Simulations

  • Packet Journey
  • DNS Lookup
  • DHCP Simulator
  • Subnet Calc
  • Network Builder
  • Terminal

Project

  • About
  • Changelog
  • GitHub
  • Contributing
  • Style guide

Newsletter

One short email when a new level ships. No tracking pixels.

© 2026 Packet.School — MIT licensed☕ Support with a coffeebuilt in the open · last updated 2026.05.14