Firewalling Basics: Difference between revisions

From 44Net Wiki
KN6DWI (talk | contribs)
Created low level and high level sections
KN6DWI (talk | contribs)
Started section on what a firewall does
Line 1: Line 1:
== 44Net Connect and Security ==  
== 44Net Connect and Security ==  
44Net Connect provides every device with a public facing IPv4 address, and does not inspect, filter, or block any traffic directed towards 44Net devices. Devices with publicly routable IP addresses face a constant barrage of traffic from various scanners and bots on the internet. Some of them are malicious, and preventing them from compromising your devices involves keeping your software up to date, configuring your firewall to prevent access to private services, and correctly configuring your software's authentication.
44Net Connect provides every device with a public facing IPv4 address, and does not inspect, filter, or block any traffic directed towards 44Net devices. Devices with publicly routable IP addresses face a constant barrage of traffic from various scanners and bots on the internet. Some of them are malicious, and correctly configuring your firewall is a key part of defending against them.
 
== What does a firewall do? ==
At its most basic, a firewall inspects incoming and outgoing packets, and based on its set of rules, decides whether each packet should be allowed through, dropped, or diverted. Rules may consider a packet's source and destination IP, source and destination interface, port, protocol (TCP vs UDP), or various special flags that may be set. Basic firewall usage is primarily concerned with source/destination IP, source/destination interface, and port. There are several goals we can achieve via firewall rules: allow outside connections to public-facing services, block outside connections to private services, and in case your device is compromised, block outgoing malicious traffic originating from your device.  
 
=== Stateful vs Stateless Firewalls ===


== Low Level Tools: iptables and nftables ==
== Low Level Tools: iptables and nftables ==

Revision as of 21:57, 21 July 2026

44Net Connect and Security

44Net Connect provides every device with a public facing IPv4 address, and does not inspect, filter, or block any traffic directed towards 44Net devices. Devices with publicly routable IP addresses face a constant barrage of traffic from various scanners and bots on the internet. Some of them are malicious, and correctly configuring your firewall is a key part of defending against them.

What does a firewall do?

At its most basic, a firewall inspects incoming and outgoing packets, and based on its set of rules, decides whether each packet should be allowed through, dropped, or diverted. Rules may consider a packet's source and destination IP, source and destination interface, port, protocol (TCP vs UDP), or various special flags that may be set. Basic firewall usage is primarily concerned with source/destination IP, source/destination interface, and port. There are several goals we can achieve via firewall rules: allow outside connections to public-facing services, block outside connections to private services, and in case your device is compromised, block outgoing malicious traffic originating from your device.

Stateful vs Stateless Firewalls

Low Level Tools: iptables and nftables

High Level Tools

firewalld

ufw