Concept · 6 min read
What is a firewall?
What does a firewall decide, and what does it happily pass through?
BeginnerCyberAtlas content
A firewall decides which flows may exist based on header fields. It is not an antivirus, an input validator, or a reason to trust anything that arrives on an allowed port.
What it sees
- Address, port, protocol, interface, direction, connection state
- Nothing about intent, authentication or the contents of an allowed request
Statefulness is the important part
A stateful firewall tracks connections so inbound traffic must belong to a session that originated inside. The practical consequence for testing: an 'unreachable' result from outside may be the state table doing its job, and a rule that permits a reply on a high port is not the same as permitting a new inbound connection there.
How testers should read the answers
bash
nmap -Pn -p 80 203.0.113.5 # closed → something answered with RST: the packet got there # filtered → no answer: dropped, or a silent rule # open → a listener completed the handshake
Where this shows up
Tools in the directory whose commands assume this knowledge.