skip to content

Firewalls & ACLs

You will learn how stateful firewalls track connections, how ACLs are evaluated top-down with an implicit deny, and how zone-based policies are structured in iptables/nftables and vendor firewalls. Interviewers probe this first because misordered rules and stateless-vs-stateful confusion are classic real-world failure modes.

on this pageshow

explore

questions

page 1 of 2

In an ordered firewall policy, a broad permit sits above a deny naming the same traffic — what reaches the server, and what does the deny still claim?

level: juniorimportance: must knowfreq 72%

answer

  1. Order decides, not intent
  2. Unreachable code, but in a policy
  3. A rule that never matches never logs
  4. The deny on the page is not evidence

basics

~20 s

The traffic arrives. The earlier permit decides and the deny below it is never evaluated. The deny still sits in the policy, still reads as an enforced control in review and audit, and never logs anything.

solid answer

~50 s

The packet is permitted. In an ordered policy the earlier rule decides, so the deny is unreachable text — the policy's author, a reviewer and an auditor all read a control that is not in effect. That asymmetry is the whole danger: a shadowed *permit* is found in hours because the requester's flow breaks and someone raises a ticket, while a shadowed *deny* produces no symptom at all. It never matches, so it never increments a counter and never writes a log line, and the permitted traffic looks like ordinary allowed business traffic in whatever logging exists. An intruder with a foothold does not need to defeat the control; they ride a path the policy claims is closed. Nothing in day-to-day operations will surface it — you only see it by reading the whole ordered policy at once and asking which rule wins each region of the match space.

go deeper

for a junior

Be ready to say plainly that the earlier rule decides and the later deny never runs, and that such a rule produces no log and no counter. Do not reach for a specificity or precedence rule that does not exist here.

for a middle

Explain why the failure is silent: an unreachable permit breaks somebody's flow and gets reported, an unreachable deny fails open with no symptom. Be able to say what evidence a zero counter does and does not carry.

for a senior

Show that you would find these by reading the exported policy as a whole rather than waiting for an operational signal, and that you treat a deny rule in an export as a claim to be verified, not as evidence of a control.

for a principal

Own the consequence for assurance: if a deny that was presented as a control turns out to be unreachable, the control was not in effect for that period, and your evidence process has to produce analysis output rather than rule text.

## The shape of the problem A classical firewall policy is an ordered list of rules, and the first rule whose match criteria cover a packet decides its fate. That much is mechanics. What matters here is the consequence at the scale of a real rulebase: a rule's effect is not a property of the rule, it is a property of the rule *plus everything above it*. When an earlier rule's match set completely covers a later rule's match set and the two carry different actions, the later rule can never fire. It is unreachable — dead text in a live document. The security-relevant case is a broad **permit above a specific deny**: ``` 20 permit 10.0.0.0/8 -> 10.5.0.0/16 tcp/3389 (added during migration) ... 90 deny any -> 10.5.0.0/16 tcp/3389 (written years earlier) ``` Rule 90 will never match a packet as long as rule 20 stands above it. The remote-desktop path into 10.5.0.0/16 that rule 90 exists to close is open to everything in 10.0.0.0/8. ## Why it is a security artefact and not just untidiness Three separate people are misled by the same page. - **The author.** Somebody wrote rule 90 deliberately, for a reason they could defend. They believe that path is closed. Their threat model, their segmentation diagram and their design document all assume it. - **The reviewer.** The permit that shadowed it arrived on its own ticket, correct in isolation and approved on its merits. - **The auditor.** A deny rule in an exported policy is routinely accepted as evidence of a control. Here it is evidence of nothing. And the fourth party is the one that turns this from a documentation defect into an incident: an intruder who already has a foothold somewhere inside 10.0.0.0/8 does not have to defeat the boundary. They enumerate what actually answers, find the path, and use it. The control was never in their way. Post-incident, the defender's own policy export argues that the traffic could not have happened. ## Why nothing raises it The usual operational signals are all silent by construction: | Signal | What it shows for a shadowed deny | |---|---| | The rule's own hit counter | Zero — it never matched | | Deny logging | Nothing — a rule that never matches never logs | | The permitted traffic's logs | Ordinary allowed traffic, indistinguishable from business flows | | The change ticket that caused it | One new permit, correct on its face | There is no alarm to miss. Note the direction of the claim carefully: a zero hit count on a deny is **not** evidence that the traffic is being blocked. Traffic that is blocked *matches* the deny and increments it. Zero means either nobody tried, or the rule is unreachable — and from the counter alone you cannot tell which. ## The asymmetry that matters Order faults come in two flavours and they behave completely differently in production: - A **permit** that is shadowed (by an earlier deny, or by an earlier permit with different treatment) has a loud failure mode. The person who requested the flow finds it broken and complains the same day. - A **deny** that is shadowed has no failure mode. It fails open, silently, forever, and the only party who benefits is someone you do not want. This is why interviewers ask about this and not about first-match evaluation in the abstract: the mechanics are simple, the consequence is not intuitive, and the failure is invisible to everything except a deliberate reading of the whole policy. ## What actually finds it Not a person reading a diff, and not the appliance — accepting a rule that some earlier rule makes unreachable is not an error condition, and the box will take it. It is found by whole-ruleset analysis: export the ordered policy, decompose the multi-dimensional match space (source, destination, port, protocol, zone) into disjoint regions, and for each region ask which rule wins. Any rule that wins no region at all is unreachable. That computation is offline and static — it needs the policy, not the traffic — which is exactly why it is available to you and also why it is easy to never run. ## The price Running that analysis on a rulebase of several thousand rules does not return one finding. It returns thousands, spread across several anomaly classes, most of which are not security defects. Detection is cheap here; deciding what to do with the output, and finding an owner for rules whose authors left the company years ago, is where the cost lands. That is the trade this leaf turns on: the control is easy to prove broken and expensive to prove safe to fix.

  • Does it matter whether the permit was added before or after the deny was written?
    No — the fault is positional, not chronological. A permit added last week near the top of the policy can silently kill a deny written five years earlier and never touched since. That is what makes it hard to attribute: the change that created the exposure looks nothing like the rule it disabled.
  • Why does nobody notice from logs?
    Because there is nothing to notice. The shadowed deny never matches, so it produces no log line and no counter movement. The traffic it should have stopped is handled by the permit above and appears, wherever it is logged at all, as ordinary allowed traffic. Silence here is indistinguishable from success.
  • Is a deny sitting below a broader permit always a defect?
    It is always dead — the deny cannot act. Whether that matters depends on what it names. Some were copied in as documentation, or as defence in depth against a rule that has since moved. The real problem is that nothing on the box tells you which kind you are looking at, so every one has to be read by a person.

It is unreachable code with a security label on it: the compiler is happy, the line reads correctly in review, and it never runs.

saying these in an interview costs you the question

  • Says the deny wins because deny is stronger than permit
  • Thinks the more specific rule wins regardless of position
  • Assumes the appliance warns when a rule becomes unreachable
  • Reads a zero hit count on a deny as proof traffic is being blocked
  • Believes the later rule refines or narrows the earlier one

context

open as a page

Why is the wide firewall permit opened at 02:00 to end an outage still an intruder's route in two years later?

level: juniorimportance: must knowfreq 68%

basics

~20 s

An emergency permit survives because nothing removes it: the change was recorded as an outage fix rather than as a permit with an end date and a named owner, and later nobody can prove that deleting the rule is safe.

open as a page

A partner-facing exchange tier terminates inbound sessions but may never open one inward — what does that deny an intruder who lands on it?

level: juniorimportance: must knowfreq 62%

basics

~20 s

It denies them a network path they can start: no socket opened from a tier host reaches an interior service. It does not deny them the tier's own data, or content the interior later collects of its own accord.

open as a page

An egress ACL at your internet edge permits only your own source prefixes: what does it stop, and who benefits?

level: juniorimportance: must knowfreq 58%

basics

~20 s

It stops hosts inside your network from putting forged source addresses onto the internet. The victim of that spoofing is almost always another network, so the filter mostly protects strangers while you pay to keep the prefix list accurate.

open as a page

An intruder pivots between two VMs on one hypervisor: why does the perimeter firewall log nothing, and what does catching that flow cost?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Two guests on one hypervisor exchange packets switched in software inside that host; nothing crosses a wire, so no border device receives them. Blocking that pivot means paying for a filter inside the host — an in-guest agent or a hypervisor firewall.

open as a page

What does an outbound rule 'allow tcp/443 to any' actually assert about the traffic it permits?

level: juniorimportance: must knowfreq 78%

basics

~20 s

Only that packets carrying destination port 443 may leave. The port number is a header field the sender chose, not a property of the application, so the rule permits whatever a host decides to send there.

open as a page

Why does a stateful firewall's session table fill with strangers when only one port is open?

level: juniorimportance: must knowfreq 65%

basics

~20 s

A rule bounds what is allowed, not how many. Permitting any source to reach port 443 lets every arriving stranger claim a session-table entry with a single packet, and those entries are a fixed, paid-for resource.

open as a page

Every firewall change passes per-ticket diff review, yet a shadowed deny let an intruder through — what does the diff never show, and what would catching it cost?

level: middleimportance: must knowfreq 58%

basics

~20 s

A diff shows one rule; reachability is a property of that rule's position against every other rule. Nothing in the ticket contains the rest of the ordered policy, so catching it means re-analysing the whole policy on every change.

open as a page

Why can a firewall rule's zero hit count mean neither that the flow is dead nor that the reach is closed?

level: middleimportance: must knowfreq 66%

basics

~20 s

A counter can read zero because a broader permit above it matched the traffic first, or because the counter was reset by a reboot or failover. Deleting a shadowed rule closes nothing; the reach lives in the rule above.

open as a page

A host firewall agent sees a flow the border sees only encapsulated — what does that visibility cost when an intruder holds root in that guest?

level: middleimportance: must knowfreq 61%

basics

~20 s

The agent stands after decapsulation, so it acts on the real inner flow and the process behind it. It also runs inside the guest, where an intruder with root can simply stop it — the sharpest vantage sits in the adversary's own privilege domain.

open as a page

What does an intruder inherit from a decade-old firewall permit that nobody can prove is dead?

level: juniorimportance: should knowfreq 58%

basics

~20 s

Reach. A permit is an enforced path from a source to a destination and port, so anyone who lands on the source side crosses it without attacking the firewall, filing a change, or raising an alert.

open as a page

Adding a vendor subnet to a firewall object group at 02:00 ends the outage: what else did it open to an intruder in that subnet?

level: middleimportance: should knowfreq 45%

basics

~20 s

Every rule that references that object group. Group membership is not scoped to the rule you were fixing, so a one-line change widens paths the change record never names — and deleting that rule later leaves the group member behind.

open as a page

Why does an interior poller pulling from a partner exchange tier move data inward without giving a compromised tier host an inward socket?

level: middleimportance: should knowfreq 50%

basics

~20 s

Because the host that opens the connection is not the host that sends the payload. The interior opens the socket outward; the response carries the data inward on that same permitted flow, so no rule ever allows a tier-initiated connection.

open as a page

Why does loose-mode uRPF on an internet edge stop far less spoofing than strict mode?

level: middleimportance: should knowfreq 46%

basics

~20 s

Strict mode requires the best route back to the packet's source to point out the interface the packet arrived on. Loose mode only asks whether the source has any route at all, so almost every routable address passes.

open as a page

Your branch ACL denies tcp/22 outbound and permits tcp/443 — how does a user still get an SSH session out?

level: middleimportance: should knowfreq 60%

basics

~20 s

By making the traffic present a permitted number: point the client at a server listening on 443, or ride an existing 443 flow as a tunnel. The deny rule never matches because no packet ever carries port 22.

open as a page

How would you size a stateful firewall's session table, and why is the idle timeout the cheapest lever?

level: middleimportance: should knowfreq 50%

basics

~20 s

Concurrent entries are roughly the new-flow arrival rate multiplied by how long an entry lives. You cannot cap arrivals from an unbounded population, so shortening the idle timeout is the only lever that shrinks the table without buying hardware.

open as a page

Whole-policy analysis of a migrated firewall rulebase returns thousands of findings — which can an intruder actually use, and what happens to a backlog you cannot staff?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Anomaly count is not risk count. Only one class means the policy permits what its author believes it denies: a deny made unreachable by an earlier permit. Rank those by what the deny names; record the rest as accepted rather than working them.

open as a page

300 emergency firewall permits never expired and each is a standing way in: how do you switch them to expiry-by-default without dropping a live clinical workflow?

level: seniorimportance: should knowfreq 52%

basics

~20 s

In two stages. First attach expiry dates and enforce nothing, publishing what would drop and when so each flow gets claimed by a named person. Then enforce in waves, lowest blast radius first, never letting a clinical path lapse unannounced.

open as a page

How long must you watch a plant boundary firewall's rule counters before deleting, and what does waiting leave open?

level: seniorimportance: should knowfreq 48%

basics

~20 s

Long enough to span the rarest legitimate flow, which at a plant is annual — the shutdown maintenance window, a vendor commissioning visit, a yearly test. Meanwhile every unproven permit stays enforced, so watch selectively rather than uniformly.

open as a page

One integration is granted an exception to open inward from the exchange tier — how do you constrain it against an intruder who owns that host, and what does keeping it cost?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Pin it to one source, one destination and a purpose-built interior endpoint, authorise it at the application layer, and assume its credential is already stolen. The cost is a standing exception with an owner, a renewal date and the precedent it sets.

open as a page

Strict uRPF goes live tonight on both transit edges of a merged estate to stop forged sources: what breaks, and what is the back-out?

level: seniorimportance: should knowfreq 34%

basics

~20 s

On a dual-transit edge, inbound traffic from any source whose best return path is the other provider is dropped the moment strict mode is armed - potentially a large slice of the internet. Enable it only where routing is symmetric, and pre-stage the removal.

open as a page

Your guests run on a provider's virtualisation cluster whose virtual switch you cannot filter at — where do you enforce against a guest-to-guest pivot, and what does it cost?

level: seniorimportance: should knowfreq 47%

basics

~20 s

With the hypervisor owned by the provider, three moves remain: mutual deny-by-default agents in every guest, a per-guest filter the provider operates, or placing workloads so the pivot must cross a path you control. Each costs money, latency or a change process.

open as a page

You deny udp/443 at a branch to keep sessions on TCP — what do you gain, and what breaks?

level: seniorimportance: should knowfreq 45%

basics

~20 s

You gain one carrier fewer to reason about: most clients that prefer QUIC fall back to TCP with TLS. You pay setup delay for everyone, and a QUIC-only client that pins its certificate breaks outright.

open as a page

Where in an ECMP leaf-spine fabric can a stateful firewall pair not stand, and why?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Anywhere both directions are not guaranteed to cross the same member. Equal-cost paths let the reply take another route, and on a VXLAN underlay the box sees tunnels rather than workloads, so it drops valid replies or is bypassed.

open as a page

Your host firewall agent can be stopped by an intruder and guests boot before policy lands — do you fail closed, and who signs that?

level: principalimportance: should knowfreq 36%

basics

~20 s

Fail-closed answers the agent failing, not an intruder who can disable the fail-closed behaviour too. Set the posture per zone, close the boot window by attaching the network only after policy loads, and have a named risk owner sign the availability exposure.

open as a page

Your exchange tier needs directory, resolution and certificate validation — why duplicate those inside it rather than let a possibly-compromised tier host query the interior copies?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Because each hole hands an untrusted zone a live interior service, and a directory or resolver answers reconnaissance questions honestly. Duplicating costs a second patch, backup and certificate lifecycle plus drift, and that bill is the price of the boundary.

open as a page

How do you prove your edge actually drops forged source addresses, and what does a clean test not prove?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

Send a packet with a source outside your prefixes from inside a segment toward a receiver you control elsewhere, and check both ends: nothing arrives, and the filter's drop counter moved. It proves that one exit path, at that moment, for a source outside your own space.

open as a page

An auditor asks what your branch's destination-port ACL prevents — what is the honest sentence, and your evidence?

level: seniorimportance: nice to knowfreq 38%

basics

~10 s

Say it prevents hosts reaching destinations on ports outside the permitted set, and claims nothing about which application crossed on a permitted port. Evidence: the rule base, its change record, and the deny logs.

open as a page

Hundreds of denies in a migrated rulebase are unreachable and an intruder can ride them, but their owners have left — what do you fund, and what do you accept?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Ask for a decision, not a tool. Detection is already solved; triage capacity and rule ownership are the constraints. Seek a named owner, an announced maintenance sequence, and authority to break unowned flows — then record what stays open as accepted.

open as a page

Firewall expiry-by-default creates a quarterly renewal review nobody will fund, and each un-renewed permit stays an intruder's route in: what do you propose?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Make renewal rare rather than free. Tier expiry by blast radius so only wide cross-zone permits face human renewal, shrink the population that qualifies, and if even that is unfunded, make a named senior owner sign for the standing exposure.

open as a page

showing 1–30 of 32