Distributed firewall

A firewall whose policy is defined centrally but enforced at many points close to the workloads, such as on each host or in the virtual switch, rather than only at the network edge.

A distributed firewall separates where policy is written from where it is enforced. Rules are defined in one central place, then pushed to enforcement points that sit next to each workload: a host-based firewall on each server, or the virtual switch or hypervisor that the workload’s traffic passes through. Steven Bellovin described the idea in a 1999 paper, and virtualised data centres made it practical at scale.

The reason for it is traffic the perimeter does not see. A firewall at the network boundary inspects traffic crossing that boundary, but traffic between systems inside it, the east-west flows, passes around it. Enforcing at every workload lets each one be protected on its own, which is how micro-segmentation is commonly enforced. Two confusions are worth avoiding. Neither micro-segmentation nor a distributed firewall is the same thing as zero trust: both are ways to enforce a zero trust design, not the design itself. And the central management system becomes a high-value target, since changing policy there changes it everywhere.

Exam relevance: a scenario is likely to describe an attacker moving laterally between servers inside a network that has only a perimeter firewall, and ask for the control that would contain it. Candidates are expected to recognise enforcement close to each workload as the answer.