fbpx

Chapter 3.1 – Basic Firewall

Firewall Basics

A firewall is a network security device or system that allows (based on a set of rules) to control traffic entering and leaving the network. Generally a firewall creates a barrier between a network that is considered secure (usually the internal network or LAN) and another network that is assumed to be unsecure (commonly an external network, and/or the Internet). The firewall filters traffic between two or more networks.

Routers that manage traffic between networks contain firewall components, and likewise some firewalls can perform certain routing functions, and can even provide tunneling services (VPN), DHCP address assignment, and others.

Basic Firewall Concepts
  • Nowadays, a firewall is an essential tool to protect our Internet connection. The fact of using an Internet connection can be the cause of multiple attacks on our computer equipment from outside. The longer we are online, the greater the probability that the security of our system will be compromised by an unknown intruder. . Therefore, it is not only necessary to have antivirus software and antispyware software installed and updated, but it is also highly recommended to have firewall software installed and updated.
  • A firewall is a system designed to prevent unauthorized access or access from a private network. Firewalls can be implemented in hardware, software, or both. Firewalls are frequently used to prevent unauthorized Internet users from accessing private networks connected to the Internet.
  • The MikroTik firewall protects your computer from Internet attacks, dangerous Web content, port scanning, and other behavior of a suspicious nature.
  • The Firewall implements packet filtering and thus provides security functions, which are used to manage the data flowing to, from, and through the router:
  • Through NAT (Network Address Translation) unauthorized access to directly connected networks and to the router itself is prevented. And it also serves as a filter for outbound traffic.
  • RouterOS works as a Stateful Firewall, which means that it performs packet state inspection and tracks the state of network connections traveling through the router.
  • RouterOS also supports:
      • Source and Destination NAT
      • NAT
      • Helpers for popular applications
      • UPnP
  • The firewall provides internal marking of connections, routing and packets.

How does a firewall work?

The Firewall operates using rules. This has 2 options:

  • The matcher : All conditions must be verified and must match in order to apply.
  • The Action : Once all the parameters match and the first verification passes, the action proceeds.

The matcher analyze and compare these following parameters:

  • Source MAC address
  • IP addresses (network or list) and address types (broadcast, local, multicast, unicast)
  • Port or port range
  • Protocol
  • Protocol options (ICMP type and code fields, TCP flags, IP options)
  • Interface through which the packet arrives or leaves
  • DSCP byte
  • And many more…

RouterOS can filter by:

  • IP address, address range, port, port range
  • IP protocol, DSCP and other parameters
  • Supports Static and Dynamic Address Lists
  • You can match packets by pattern in their content, specified in Regular Expressions, known as Layer 7 matching

RouterOS Firewall also supports IPv6

A firewall constitutes a kind of barrier in front of our computer, this barrier examines each and every information packet that tries to pass through it. Based on previously established rules, the firewall decides which packets should pass and which should be blocked. Many types of firewalls are capable of filtering data traffic that tries to leave our network outside, thus preventing different types of malicious code such as Trojan horses, viruses and worms, among others, from being effective. The firewall acts as an intermediary between our computer (or our local network) and the Internet, filtering the traffic that passes through it.

A firewall, as already described, intercepts each and every packet destined for and coming from our computer, doing this job before any other service can receive them. From the above we can conclude that a firewall can control all communications of a system over the Internet.

A communications port is said to be open if the system returns a response when a connection establishment request packet arrives. Otherwise the port is considered closed and no one can connect to it. The strength of a firewall is that by analyzing each packet that flows through it, it can decide whether to let it pass in one direction or another, and it can decide whether connection requests to certain ports should be responded to or not.

Firewalls are also characterized by their ability to maintain a detailed record of all traffic and connection attempts that occur (known as a log). By studying the logs it is possible to determine the origins of possible attacks and discover communication patterns that identify certain malicious programs. Only users with administrative privileges can access these logs, but it is a feature that can be required of these applications.

https://help.mikrotik.com/docs/display/ROS/Basic+Concepts

There are no tags for this post.
Did this content help you?
Facebook
Twitter
LinkedIn
WhatsApp
Telegram

Other documents in this category

Leave your comment

Your email address will not be published. Required fields are marked with *

Tutorials available at MikroLABs

No Courses Found!

DISCOUNT CODE

AN24-LIB

applies to MikroTik books and book packs

Days
Hours
Minutes
Seconds

Introduction to
OSPF - BGP - MPLS

Sign up for this Free course

MAE-RAV-ROS-240118
Days
Hours
Minutes
Seconds

Sign up for this Free course

MAS-ROS-240111

Promo for Three Kings Day!

KINGS24

Present in several = 15%

all the products

MikroTik courses
Academy courses
MikroTik books

Take advantage of the Three Kings Day discount code!

* promotion valid until Sunday January 7, 2024
** the code (KINGS24) applies to shopping cart
*** buy your course now and take it until March 31, 2024

New Year's Eve Promo!

NY24

Present in several = 20%

all the products

MikroTik courses
Academy courses
MikroTik books

Take advantage of the New Year's Eve discount code!

* promotion valid until Monday, January 1, 2024
** the code (NY24) applies to shopping cart
*** buy your course now and take it until March 31, 2024

Christmas discounts!

XMAS23

Present in several = 30%

all the products

MikroTik courses
Academy courses
MikroTik books

Take advantage of the discount code for Christmas!!!

**codes are applied in the shopping cart
Promo valid until Monday December 25, 2023

CYBER WEEK DISCOUNTS

CW23-MK

Present in several = 17%

all MikroTik OnLine courses

CW23-AX

Present in several = 30%

all Academy courses

CW23-LIB

Present in several = 25%

all MikroTik Books and Book Packs

Take advantage of the discount codes for Cyber ​​Week!!!

**codes are applied in the shopping cart
Promo valid until Sunday December 3, 2023

BLACK FRIDAY DISCOUNTS

BF23-MX

Present in several = 22%

all MikroTik OnLine courses

BF23-AX

Present in several = 35%

all Academy courses

BF23-LIB

Present in several = 30%

all MikroTik Books and Book Packs

Take advantage of the discount codes for Black Friday!!!

**Codes are applied in the shopping cart

codes are applied in the shopping cart
valid until Sunday November 26, 2023

Days
Hours
Minutes
Seconds

Sign up for this Free course

MAE-VPN-SET-231115

Halloween promo

Take advantage of discount codes for Halloween.

Codes are applied in the shopping cart

HW23-MK

11% discount on all MikroTik OnLine courses

11%

HW23-AX

30% discount on all Academy courses

30%

HW23-LIB

25% discount on all MikroTik Books and Book Packs

25%

Register and participate in the free course Introduction to Advanced Routing with MikroTik (MAE-RAV-ROS)

Today (Wednesday) October 11, 2023
7pm to 11pm (Colombia, Ecuador, Peru)

MAE-RAV-ROS-231011