Firewall Virtual Lab: Rule Order, Default Deny and Access

Updated 2026-10-08

This firewall virtual lab adds a hands-on investigation to the network-security unit of GCSE and IGCSE computer science. Students repair a school firewall's rule list, read the firewall log to see which rule decided each packet, and test two ideas exam questions return to: the first matching rule wins, and anything not explicitly allowed should be dropped. They finish by setting file permissions with least privilege. The modelled network uses documentation-only addresses: the lab is purely defensive. Every value below was read from the simulation.

Firewalls and access control – packet-filter rules and least privilege
  • OCR GCSE Computer Science (J277) 1.4.2: identifying and preventing vulnerabilities, including firewalls and user access levels.
  • AQA GCSE Computer Science (8525): network security methods, including firewalls (section 3.5), and cyber security (section 3.6).
  • Cambridge IGCSE Computer Science (0478): cyber security measures, including firewalls and access levels.
  • CSTA K–12 Computer Science Standards (grades 9–10), Networks and the Internet: recommending security measures and weighing security against usability.

Simulic is not affiliated with or endorsed by OCR, AQA, Cambridge International or CSTA.

Before the lab (5 min)

Ask students to commit to a prediction, on paper or as question 1 of the class link:

"A firewall's rule list meets all its security goals. You add the rule Deny, In, Any source, Any port and move it to the top. What happens?"

Many students expect the specific allow rules below to win.

Method in the simulation

Part A: fix the faulty set

  1. On the Firewall tab (it opens first), keep Starting rules "Faulty set to fix" and Default policy "Drop (default deny)". Set Traffic to 8 per second. Record the caption Security goals: …/7 met.
  2. When an SSH packet from 198.51.100.66 appears in the Firewall log, press Pause and note its Rule and Result. Then Resume.
  3. Change Default policy to "Pass (default allow)", press Clear log, wait 30 seconds and record the goals and the status line. Change back to Drop.

Part B: rule order

  1. Choose Starting rules "Example solution". Press Add rule: rule 8 is Deny, In, Any, Any, Any. Record the goals met.
  2. Press ↑ on the new rule until it is rule 1. Record the goals met and which fail.

Part C: least privilege

  1. Open the File permissions tab. With Starting permissions "Everyone has every permission", record the score line. Under Try access, choose Ben, write (W), Marks.xlsx and press Try.
  2. Choose "Least privilege (example solution)" and repeat step 6.
Step Setup Goals met or score Log or test result
1–2 Faulty set, Drop
3 Faulty set, Pass
4 Deny at rule 8
5 Deny at rule 1
6 Everyone has every permission
7 Least privilege

the Firewall tab on a freshly opened page (Starting rules "Faulty set to fix", Default policy "Drop (default deny)"), with the goals table captioned "Security goals: 3/7 met" and ✗ beside the website, email, SSH and online-games goals

Expected results

  • Faulty set, Drop: 3/7. No rule allows HTTPS or incoming email, so the default drops them. Rule 2 allows SSH from any address, so the unknown host gets in, and rule 3 lets every outgoing packet out, games included. In our 311-packet run, 53 (17%) got through that should have been blocked and 75 needed packets (24%) were dropped.
  • Faulty set, Pass: 4/7. Website and email work, but Telnet, RDP and SMB from the unknown host pass too: 104 of our 323 packets (32%) should have been blocked.
  • Example solution: 7/7. With the new Deny at rule 8, still 7/7: the default already drops unmatched incoming packets. At rule 1 it drops every incoming packet before any allow rule is read: 4/7, with the website, email and admin SSH goals failing.
  • Everyone has every permission: "15/15 work needs met · 29 extra permissions". Only 15 of the 44 permissions are needed (34%), and Ben, a student, may write to Marks.xlsx.
  • Least privilege: "15/15 work needs met · 0 extra permissions", and Ben's write is denied.

Questions for students

  1. (Prediction, asked again after the lab) What happens when Deny, In, Any, Any goes to the top of a working list?
  2. In the rule-order test, which is the independent variable?
  3. How many goals are met with the new Deny rule at rule 1?
  4. What percentage of the permissions granted at the open start are needed?
  5. Why is switching the faulty set to default Pass not a fix, and how is default deny like least privilege?

Answers for teachers: (1) Every incoming packet is dropped. (2) The Deny rule's position. (3) 4. (4) Accept 33–35% (15 ÷ 44). (5) Pass met one more goal only because unmatched traffic now passes, Telnet, RDP and SMB included, and so would any new service or attacker. Both principles allow only what is needed and refuse the rest.

Common misconceptions

  • "The most specific rule wins." The firewall stops at the first match, so a broad Deny at rule 1 hides every allow rule below it.
  • "More goals met means safer." Pass met 4 goals to Drop's 3 but let through about twice the share of unwanted packets.
  • "Fewer rules are always better." A 4-rule list can meet 7/7 by allowing every port from 203.0.113.0/24: shorter, but broader.

Extension

  • Shortest list: from "Empty (default only)", meet 7/7 with as few rules as possible. A search of every combination found Drop needs at least 4 rules, Pass only 3. Which list stays safe if a new service appears?
  • Wrong group: move Chloe into Teachers and explain the warning.

FAQ

Is it safe to teach firewall rules this way?

Yes. Students configure defences on a modelled network; nothing leaves the page.

Can I choose the starting rules or open on the permissions tab?

Yes. In the class link's starting values, set Starting firewall rules, Firewall default policy, Starting group permissions or Opening screen ("File permissions"). Keep "Faulty set to fix": "Example solution" gives the answer away.

Why do my students' log counts differ?

Packets arrive at random, so the status line and hit counts vary. The goals table and permissions score don't, so questions 3 and 4 have one answer.

TCP/IP layers – encapsulation, MAC and IP addresses, TCP vs UDP Malware spreading in a network – testing cyber defences

For running the prediction step, see predict, observe, explain with simulations.