๐Ÿ”ฅ Firewalls ยท Proxies ยท ACLs

Interactive Network Security Demo โ€” CS 423/623/723

๐Ÿ”ฅ How It Works

A firewall inspects packets at Layer 3/4 (IP & TCP/UDP headers) and decides whether to allow or deny traffic based on a sequential rule set. Rules are matched top-down โ€” the first matching rule wins. An implicit deny all is typically the last rule.

Stateful Packet Filter Layer 3/4 Default Deny

๐Ÿ“‹ Firewall Rules

#Src IPDst PortProtoAction
110.0.0.*80TCPALLOW
210.0.0.*443TCPALLOW
3192.168.1.*22TCPALLOW
4*22TCPDENY
5***DENY

๐Ÿงช Simulate a Packet

๐Ÿ’ป
Client
๐Ÿ”ฅ
Firewall
๐Ÿ–ฅ๏ธ
Server
Configure a packet and click "Send Packet" to see how the firewall processes it.

๐ŸŒ How It Works

A proxy acts as an intermediary at Layer 7 (Application). Clients connect to the proxy, which opens a separate connection to the destination. The proxy can inspect, filter, cache, and modify application-layer content โ€” including URLs, HTTP headers, and payloads. The destination only sees the proxy's IP, hiding the client.

Layer 7 Content Inspection IP Masking Caching

๐Ÿ“‹ Proxy Policy

#URL PatternMethodContentAction
1*.edu/***ALLOW
2*.google.com/*GET*ALLOW
3*.malware.xyz/***BLOCK
4*POSTSSN/CC#BLOCK
5*GET*ALLOW

๐Ÿงช Simulate a Request

๐Ÿ’ป
Client
๐ŸŒ
Proxy
๐Ÿ–ฅ๏ธ
Web Server
Configure a request and click "Send Request" to see how the proxy processes it.

๐Ÿ” How It Works

An Access Control List (ACL) is a set of permit/deny rules applied to a router interface. ACLs filter traffic as it enters (inbound) or exits (outbound) an interface. Standard ACLs (1-99) filter by source IP only. Extended ACLs (100-199) can match source/dest IP, ports, and protocols. Like firewalls, rules are checked top-down with an implicit deny.

Router-Level Standard vs Extended Interface-Bound Implicit Deny

๐Ÿ“‹ Extended ACL 101 (Inbound on Gi0/0)

#Src IPDst IPPortAction
1010.0.1.*172.16.0.1080PERMIT
2010.0.1.*172.16.0.10443PERMIT
3010.0.2.*172.16.0.2022PERMIT
40*172.16.0.20*DENY
--***DENY

๐Ÿงช Simulate a Packet

๐Ÿ’ป
Host
๐Ÿ”
Router ACL
๐Ÿ–ฅ๏ธ
Server
Configure a packet and click "Send Packet" to see how the ACL processes it.

๐Ÿ“Š Side-by-Side Comparison

Feature๐Ÿ”ฅ Firewall๐ŸŒ Proxy๐Ÿ” ACL
OSI Layer Layer 3/4 (Network/Transport) Layer 7 (Application) Layer 3/4 (Network/Transport)
Inspects IP headers, ports, protocol flags URLs, HTTP headers, content body, cookies Source/Dest IP, ports, protocol
Deployment Network perimeter (dedicated device or software) Inline or explicit config on clients On router interfaces (inbound/outbound)
Statefulness Stateful โ€” tracks connection state Fully application-aware; can cache & modify Typically stateless (checks each packet independently)
Client Visibility Transparent โ€” clients don't know it's there Client IP hidden from server; proxy IP exposed Transparent โ€” applied by router
Granularity Medium โ€” IP + port + protocol rules High โ€” can filter by URL path, content type, payload Low-Medium โ€” IP + port (extended) or IP only (standard)
Use Cases Perimeter defense, zone segmentation, DMZ Web filtering, caching, anonymization, DLP Inter-VLAN filtering, router-level access control
Example Block all inbound SSH except from admin subnet Block uploads containing SSNs to non-.edu sites Permit VLAN 10 โ†’ Web Server on port 80 only