Interactive Network Security Demo โ CS 423/623/723
A firewall inspects packets at Layer 3/4 (IP & TCP/UDP headers) and decides whether to allow or deny traffic based on a sequential rule set. Rules are matched top-down โ the first matching rule wins. An implicit deny all is typically the last rule.
| # | Src IP | Dst Port | Proto | Action |
|---|---|---|---|---|
| 1 | 10.0.0.* | 80 | TCP | ALLOW |
| 2 | 10.0.0.* | 443 | TCP | ALLOW |
| 3 | 192.168.1.* | 22 | TCP | ALLOW |
| 4 | * | 22 | TCP | DENY |
| 5 | * | * | * | DENY |
A proxy acts as an intermediary at Layer 7 (Application). Clients connect to the proxy, which opens a separate connection to the destination. The proxy can inspect, filter, cache, and modify application-layer content โ including URLs, HTTP headers, and payloads. The destination only sees the proxy's IP, hiding the client.
| # | URL Pattern | Method | Content | Action |
|---|---|---|---|---|
| 1 | *.edu/* | * | * | ALLOW |
| 2 | *.google.com/* | GET | * | ALLOW |
| 3 | *.malware.xyz/* | * | * | BLOCK |
| 4 | * | POST | SSN/CC# | BLOCK |
| 5 | * | GET | * | ALLOW |
An Access Control List (ACL) is a set of permit/deny rules applied to a router interface. ACLs filter traffic as it enters (inbound) or exits (outbound) an interface. Standard ACLs (1-99) filter by source IP only. Extended ACLs (100-199) can match source/dest IP, ports, and protocols. Like firewalls, rules are checked top-down with an implicit deny.
| # | Src IP | Dst IP | Port | Action |
|---|---|---|---|---|
| 10 | 10.0.1.* | 172.16.0.10 | 80 | PERMIT |
| 20 | 10.0.1.* | 172.16.0.10 | 443 | PERMIT |
| 30 | 10.0.2.* | 172.16.0.20 | 22 | PERMIT |
| 40 | * | 172.16.0.20 | * | DENY |
| -- | * | * | * | DENY |
| Feature | ๐ฅ Firewall | ๐ Proxy | ๐ ACL |
|---|---|---|---|
| OSI Layer | Layer 3/4 (Network/Transport) | Layer 7 (Application) | Layer 3/4 (Network/Transport) |
| Inspects | IP headers, ports, protocol flags | URLs, HTTP headers, content body, cookies | Source/Dest IP, ports, protocol |
| Deployment | Network perimeter (dedicated device or software) | Inline or explicit config on clients | On router interfaces (inbound/outbound) |
| Statefulness | Stateful โ tracks connection state | Fully application-aware; can cache & modify | Typically stateless (checks each packet independently) |
| Client Visibility | Transparent โ clients don't know it's there | Client IP hidden from server; proxy IP exposed | Transparent โ applied by router |
| Granularity | Medium โ IP + port + protocol rules | High โ can filter by URL path, content type, payload | Low-Medium โ IP + port (extended) or IP only (standard) |
| Use Cases | Perimeter defense, zone segmentation, DMZ | Web filtering, caching, anonymization, DLP | Inter-VLAN filtering, router-level access control |
| Example | Block all inbound SSH except from admin subnet | Block uploads containing SSNs to non-.edu sites | Permit VLAN 10 โ Web Server on port 80 only |