1What a firewall decides
This is your copy to keep.
A firewall sits between networks and decides, for each packet, whether to let it through. At a client site it is usually the same physical box as the gateway, so every packet leaving the building, arriving from the internet, or crossing between two internal networks passes through it.
It decides against a list of rules, and each rule matches on some combination of four things: where the packet came from, where it is going, which protocol it is, and which port it is for, where a port is a number from 0 to 65535 in the packet saying which program on the destination machine the data is for.
Two things make this worth an hour rather than a paragraph. The order the rules are read in changes the outcome, and a firewall keeps track of conversations already in progress, which is why most traffic needs no rule of its own at all.
The addresses on this page are an example written for training. They are not a client network. The example site has staff on 192.168.10.0/24, voice on 192.168.20.0/24 and guest on 192.168.30.0/24, with the gateway at .1 on each.
2Why a reply gets back in without a rule
A workstation at 192.168.10.15 loads a website. The request goes out, and the answer
comes back in from the internet. Nothing on the internet side is trusted, and no rule was written
permitting that website to send anything to that workstation. So why does the answer arrive?
Because the firewall wrote the request down. When the request left, the firewall recorded the source address and port, the destination address and port, and the protocol, in a state table. When a packet arrives from outside, the firewall checks it against that table first. A packet that matches a conversation already in progress is part of something this network started, so it is allowed through without consulting any rule. This is called stateful inspection.
The consequences run through everything else in this session.
- Rules are needed for traffic that starts somewhere, not for every packet. Permitting the staff network to reach the internet is one rule, and every reply to every request comes back on its own.
- Traffic starting on the outside matches nothing in the table, so it is judged by the rules alone. That is the asymmetry the whole design rests on: out is easy, in is deliberate.
- Entries expire. A conversation with nothing crossing it for long enough is dropped from the table, and the next packet is treated as a new arrival from outside and blocked. This is why an idle remote session or an idle database connection dies while an active one does not.
3Rule order
Rules are read top to bottom and the first one that matches decides the packet. Nothing below it is consulted. That single sentence causes most of the confusion people have with firewalls, so work an example.
| Order | Rule | What it does |
|---|---|---|
| 1 | Block guest network to all internal networks | Matches everything from guest heading anywhere internal |
| 2 | Allow guest network to the internal printer | Never reached, for any packet |
A guest device sending to the printer matches rule 1, which blocks it, and the firewall stops reading. Rule 2 is not wrong and it is not disabled. It is simply never consulted, because something above it already decided every packet it would have matched. Swap the two and the printer works while everything else from guest is still blocked.
Stated as the rule: the specific exception goes above the general block, never below it.
At the bottom of every rule list sits a decision that applies to anything no rule matched, and on a firewall worth using that decision is to block. It is called the implicit deny, and it is why you write rules for what is permitted rather than rules for what is forbidden: the list of things to forbid has no end, and the list of things a business actually needs is short and knowable.
4Zones
Writing a rule for every pair of networks does not scale. Six internal networks make thirty pairs, and every new network makes more. The answer is to group interfaces into zones and write rules between zones instead.
The UniFi gateway ships with six zones, and knowing what each one contains is most of reading somebody else's rule list.
| Zone | What is in it |
|---|---|
| External | Untrusted incoming traffic: the internet, and third-party connections to other organizations |
| Internal | Trusted local networks |
| Gateway | Traffic to and from the gateway itself, such as its own management interface |
| VPN | Remote user connections and permanent connections to other offices |
| Hotspot | Restricted guest access |
| DMZ | Anything deliberately reachable from outside, kept apart from the internal networks |
A rule then reads as a sentence: from this zone, to that zone, this traffic, allow or block. Custom rules are evaluated before the built-in ones and in the order you place them among themselves, so the ordering rule from the previous section applies within your own list.
DMZ is the one worth explaining rather than naming. It is a network for machines that have to be reachable from the internet, arranged so that a machine in it cannot reach the internal networks. If such a machine is compromised, the attacker has the machine and no route onward, which is the entire purpose of putting it there.
5What address translation does
The private address ranges, including the 192.168 addresses at every site, are not routed on the internet. A packet with a source address of 192.168.10.15 could never be answered, because that address exists in a million buildings and names none of them.
NAT (network address translation) is what solves it. On the way out, the firewall rewrites the source address to its own public address, and records the swap so it can undo it when the answer comes back.
Follow one request, with the site's public address as 203.0.113.20.
- The workstation sends from 192.168.10.15, source port 51900, to a web server at 198.51.100.7 on port 443.
- The firewall rewrites the source to 203.0.113.20 and picks a port of its own, say 40001. It writes down that 203.0.113.20 port 40001 means 192.168.10.15 port 51900.
- The web server sees a request from 203.0.113.20 port 40001 and answers to exactly that.
- The firewall receives the answer, looks up port 40001 in its table, rewrites the destination back to 192.168.10.15 port 51900, and delivers it.
The port is what makes this work for a whole building rather than one machine. Every outbound conversation gets its own port number on the public address, so hundreds of machines share one public address and every answer still finds its way back to the right one.
It also means the internet never learns an internal address. That is a side effect rather than a security design, and it is worth being precise about: translation hides the addresses, and the firewall rules are what actually decide who gets in.
6Port forwarding, and why to avoid it
Translation handles traffic a site starts. Traffic starting outside has nowhere to go: a packet arriving at 203.0.113.20 matches no entry in the table, and the firewall has no way to know which internal machine it was meant for.
Port forwarding supplies the missing instruction. It says that anything arriving on a named public port belongs to a named internal machine and port. In the UniFi console the fields are the rule name, which WAN interface it applies to, the incoming public address and port, whether to accept from any source or only named ones, the internal destination address and port, and the protocol.
What it actually creates is a permanent opening from the entire internet to one service on one internal machine. Everything on the internet that scans for open ports finds it, usually within hours, and whatever is behind it is exposed continuously rather than when somebody is using it.
The two fields that reduce that risk are on the same form. Restricting the source to named addresses turns an opening for everybody into an opening for one partner. Forwarding to a non-obvious external port does not stop a scanner and is worth nothing on its own.
The single most damaging rule in small business networks is a forward of port 3389, remote desktop, to a server. It puts a sign-in prompt for that machine in front of the whole internet, and automated attempts against it begin within hours of the rule being created. Remote access to a machine belongs behind an encrypted connection that authenticates first, which is what the next section is about. When you are asked for a remote desktop forward, that is the answer to give.
7VPN as a special case
A VPN (virtual private network) is an encrypted tunnel across the internet that makes a remote machine or a remote office behave as though it were attached to the local network. It appears in the firewall as its own zone, so traffic arriving through it is judged by rules like anything else rather than being trusted automatically.
Remote access
One person, from a laptop anywhere. They authenticate, a tunnel is built, and their machine is given an address that lets it reach what the rules permit.
This is what replaces a port forward for remote work. The authentication happens before anything internal is reachable, and there is no permanently open service on the public address.
Site to site
Two offices joined permanently, so machines at each site reach the other by internal address as though it were one network.
Both ends need a route to the other's network, and the address ranges at the two sites must not overlap. Two sites both using 192.168.1.0/24 cannot be joined until one is renumbered, because every address would name a machine at both ends.
The common mistake with either kind is assuming the tunnel grants access. It grants reachability. What the remote machine may then do is still a rule, from the VPN zone to the internal zone, and a tunnel that connects successfully while nothing works is almost always that rule missing rather than the tunnel failing.
8Reading a blocked-traffic log
A firewall can log what it blocked. The log is useful once you can read a line, and a line has the same shape everywhere: a time, a source address and port, a destination address and port, a protocol, and the rule that decided it.
| Source | Destination | Reading | What to do |
|---|---|---|---|
| An address on the internet, many different sources | The public address, port 3389 | Automated scanning for remote desktop. Constant background noise on every public address | Nothing, as long as nothing is forwarded there. It is evidence for why nothing should be |
| 192.168.30.41, a guest device | 192.168.10.50, port 445 | A guest device trying to reach an internal file share, blocked by design | Nothing to the firewall. Worth knowing whose device it is, because it is usually a staff phone on the wrong network |
| 192.168.10.15, a staff workstation | An external address, port 443 | Ordinary work being blocked. Something a user is trying to do is not permitted | Find out what the destination is before adding anything. The block may be correct |
The discipline that matters is the last row. A blocked entry is a fact about what was attempted, not a request for a rule. Before any rule is added, three things need answering: what the traffic is, who asked for it, and whether the same need can be met by something already permitted. A rule added to clear a log line outlives the ticket by years and nobody afterwards knows why it is there.
9Practice
- In the UniFi console, open a site's firewall rules and read them top to bottom. For each custom rule, write it as a sentence: from this zone, to that zone, this traffic, allowed or blocked.
- Find a rule pair where a specific exception sits above a general block. Say what would happen if the two were swapped.
- Find the site's port forwarding rules, if any. For each, write down the public port, the internal machine and port, and whether the source is restricted. Say what is exposed by each one.
- Open the blocked-traffic log and classify twenty lines into the three kinds in section 8: scanning from outside, internal traffic blocked by design, and ordinary work being blocked.
- Pick one line of the third kind and work out what the user was trying to do, without adding a rule.
10Check for understanding
A workstation loads a website. No rule permits that website to send anything in. Explain why the answer arrives anyway, and what would have to be true for it not to.
A rule list blocks the guest network from all internal networks at position 1 and permits guest to the internal printer at position 2. Guests cannot print. What is wrong, and what is the fix?
What is the implicit deny, and why does it mean rules are written for what is permitted rather than for what is forbidden?
Describe what NAT does to a packet on the way out and on the way back, and say what the port number is doing in that process.
A client asks for remote desktop to be forwarded to their server so they can work from home. Give the answer you would give and the reason, and say what to offer instead.
A remote user's VPN connects successfully and shows as established, but they cannot reach any internal machine. What is the most likely cause, and why is a connected tunnel not evidence against it?
A remote desktop session to a server drops every time the user leaves it alone for a while, and never drops while they are working in it. The network is otherwise healthy. What is happening?
11Before the next session
- Do the practice steps in section 9 and bring your twenty classified log lines.
- Be able to state the ordering rule and the implicit deny in one sentence each.
- Read the Network+ companion, chapter 5, the sections on security devices and secure protocols.
Next session. 07 - Wi-Fi. The last session of this course: why a shared radio medium behaves differently from a cable, and how to drive a slow wireless complaint to a cause.
12Glossary
- Firewall
- The device that decides, packet by packet, what may pass between networks.
- Port
- A number from 0 to 65535 in a packet saying which program on the destination machine the data is for.
- State table
- The firewall's record of conversations in progress, used to recognize replies to traffic this network started.
- Stateful inspection
- Judging a packet by whether it belongs to a conversation already in progress, before consulting any rule.
- Implicit deny
- The decision applied to anything no rule matched. On a firewall worth using, it is to block.
- Zone
- A group of interfaces treated together, so rules are written between groups rather than between every pair of networks.
- DMZ
- A network for machines that must be reachable from the internet, arranged so they cannot reach the internal networks.
- NAT
- Network address translation. Rewriting a private source address to the site's public address on the way out, and undoing it on the way back.
- Port forwarding
- A rule sending traffic arriving on a public port to a named internal machine and port. A permanent opening from the internet to that service.
- VPN
- Virtual private network. An encrypted tunnel across the internet that makes a remote machine or office behave as though attached to the local network.
- Remote access VPN
- A tunnel for one person from one machine, built after they authenticate.
- Site-to-site VPN
- A permanent tunnel joining two offices, requiring a route at each end and non-overlapping address ranges.
- WAN interface
- The connection facing the internet, as opposed to the internal networks.
13Sources
- Internet Engineering Task Force, RFC 3022, Traditional IP Network Address Translator, for address and port translation and the table that reverses it.
- Internet Engineering Task Force, RFC 2979, Behavior of and Requirements for Internet Firewalls, for stateful behavior and default-deny.
- Ubiquiti, Zone-Based Firewalls in UniFi, for the six built-in zones and how custom rules are ordered against built-in ones.
- Ubiquiti, UniFi Gateway, Port Forwarding, for the fields on a forwarding rule.
- Ubiquiti, Traffic and Policy Management in UniFi.
- Cybersecurity and Infrastructure Security Agency, Securing Network Infrastructure Devices, on limiting services exposed to the internet.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 5, security devices and secure protocols.