Unit content
Packet filtering and stateful firewalls
A firewall enforces network policy by deciding which traffic may cross a boundary.
A stateless packet filter can match fields such as source and destination addresses, transport protocol and ports. A stateful firewall also tracks connection or flow state, allowing return traffic associated with a permitted outbound connection while rejecting unrelated unsolicited packets.
For example, a policy may permit internal clients to initiate TCP connections to web servers. The firewall records those flows and accepts matching replies without opening the same inbound destination ports to arbitrary external initiators.
Firewalling is distinct from NAT: a device may perform both, but translation rewrites addressing while filtering makes an authorization decision.
Firewalls reduce exposed network reachability, but they do not prove application safety. Traffic explicitly allowed through the firewall can still exploit vulnerabilities in the reachable service.