Firewalls and access control – packet-filter rules and least privilege

Computer ScienceDigital Safety & EthicsAges 15–16

Loading…

Use with my class ✨ Customize with AI Report a problem

Write rules for a packet-filter firewall (allow or deny by direction, protocol, source IP address and destination port; the first matching rule decides; default deny) and watch web, email, SSH, game and unknown traffic pass or get dropped, checked against seven security goals. Then give each user group read, write and execute permissions on files and folders following the principle of least privilege, test who can do what and read the access log.

Lesson: Network security: firewalls, packet-filter rules, ports, user access levels and the principle of least privilege

What it shows

A packet-filter firewall reads the header of every packet – direction, protocol, source IP address and destination port – and compares it with an ordered list of rules. The first rule that matches decides whether the packet is allowed or dropped; if no rule matches, the default policy applies. The safe pattern is default deny plus a few allow rules for the services that are really needed. Inside the network, access control does the same job for data: each user belongs to a group, and each group gets only the read, write and execute permissions its work requires.

How to use

On the Firewall tab, pick Starting rules and a Default policy, then edit the rule table: change any field, move rules up or down, delete them or use Add rule. Watch the packets and the firewall log, and aim for 7 of 7 security goals. On the File permissions tab, click R, W and X to set each group's permissions, press Check each cell, change a user's group and use Try access to test one request.

Parameters you can change

  • Opening screen Firewall, File permissions
  • Starting firewall rules Faulty set to fix, Empty (default only), Example solution
  • Firewall default policy Drop (default deny), Pass (default allow)
  • Traffic (packets or requests per second) 1–8
  • Starting group permissions Everyone has every permission, Nobody has any permission, Least privilege (example solution)

Questions to explore

  1. Why does the order of the rules matter when the first matching rule decides?
  2. Why is default deny safer than default allow, even if every allow rule looks correct?
  3. Which permissions can you remove from the open start without stopping anyone's work, and what risk does each one carry?