← Explorations
Firewalls & Network Defenses
Stateful vs stateless. IDS vs IPS. NAT, DMZ, segmentation.
Which firewall fits this scenario?
 
The seven firewall types · click any to see what it does
Stateful vs Stateless

A stateless firewall checks each packet in isolation, so it needs an explicit rule for every direction. A stateful firewall remembers connections it has seen and automatically allows the return traffic. Almost every modern firewall is stateful.

Which network defense is this?
 

DMZ: where the public stuff goes

A semi-trusted zone sits between the internet and the trusted internal network. Public servers (web, mail, DNS) live here so a compromise does not immediately reach internal systems.

Internet

Untrusted, hostile by default.
EVERYONE
Firewall

DMZ

Semi-trusted. Hosts services reachable from the internet.
Public web, mail relay, public DNS
Firewall

Internal

Trusted. Workstations, databases, internal apps.
Employees, internal apps
Network defenses cheat sheet
IDS
Detects and alerts. Sits out-of-band. Does not block.
IPS
Detects, alerts, AND blocks. Sits inline in the traffic path.
NAT
Translates private IP addresses to a public IP. Hides internal addressing.
PAT
Many internal hosts share one public IP by tracking source ports. Home routers do this.
Forward proxy
Acts on behalf of clients. Used for content filtering and caching.
Reverse proxy
Acts on behalf of servers. Used for load balancing and TLS handling.
VLAN
Logically splits one switch into multiple broadcast domains for segmentation.
Segmentation
Splits the network into zones so a compromise in one zone does not roam everywhere.
Score: 0 / 0 (0%)
Streak: 0