Packet-filtering firewall

A stateless firewall that allows or denies each packet on its own by matching header fields, such as addresses, ports and protocol, against an ordered rule list.

A packet-filtering firewall is the first generation of firewall. It examines each packet in isolation and compares header fields, chiefly source and destination IP address, source and destination port, and protocol, against an ordered list of rules, usually with a final rule that denies anything not explicitly allowed. It works at the network and transport layers and does not read the payload. Access control lists on a router are a common form: cheap, fast and widely available.

Being stateless is the weakness candidates are expected to understand. The filter has no memory of earlier packets, so it cannot tell whether an incoming packet is a genuine reply to a connection someone inside opened. Rules for return traffic therefore have to be broad, and crafted packets, fragments and spoofed source addresses can slip through. A stateful inspection firewall tracks each session to close that gap, a circuit-level gateway validates the session set-up, an application-level gateway inspects the content as a proxy, and a next-generation firewall adds application awareness. It remains useful as a fast first layer, for example for ingress filtering.

Exam relevance: a scenario that describes decisions based only on addresses and ports, with no connection tracking, is likely to point to a packet-filtering firewall. Candidates are expected to place it correctly among the firewall generations.