What is a Packet Filter? | Perimeter81 Glossary

Network Security

ben kazinik

30.10.2023

7 min read

What is a Packet Filter?

Packet filtering involves permitting or blocking data packets at a network interface based on source, destination, ports, and protocols. Examining IP packet headers, packet filtering follows predefined rules to either allow (accept) or prevent (drop) packet transmission.

Table of Contents

What is Packet Filtering Used For?

Packet filtering serves the crucial purpose of controlling and monitoring network data to ensure its integrity and compliance, ultimately enhancing system performance, safeguarding valuable assets, and facilitating seamless operations within your network.

It is particularly effective in defending against external network attacks on internal LANs and is considered a cost-effective security method due to its widespread implementation in routing devices.

The unique protective capabilities of packet filtering firewalls are essential. Rejecting packets with internal source addresses, which are often used in IP spoofing attacks, is a key decision made by filtering firewalls at the network’s perimeter.

This decision is critical as it prevents attackers from disguising themselves as internal machines. Only a boundary-filtering firewall has the capability to differentiate between internal and external network origins by analyzing source IP addresses.

The Rules of Packet Filtering

Packet filtering, situated at the network layer of the OSI Model, evaluates data packets using predetermined rules that administrators set to decide whether packets should be allowed or blocked.

These rules encompass various factors, including source and destination IP addresses, ports, network protocol, IP flags, firewall interface, and traffic direction. Often, these rules are combined with a specific order of precedence to form an overarching policy.

For example, in managing employee internet traffic, these rules can be structured as follows:

  1. Permit trusted File Transfer Protocol traffic to a specific IP address.
  2. Restrict traffic to known malicious IP addresses.
  3. Authorize a specific internal IP address to access a designated file-sharing IP address.
  4. Prohibit traffic to file-sharing IP addresses for all other internal IP addresses.
  5. Allow web traffic on commonly used ports 80 and 443.
  6. Block all other traffic types.

Packet filter firewalls are designed to operate efficiently without retaining knowledge of past network traffic, ensuring swift decision-making for each packet based on these predefined rules.

Elements of Package of Filtering

Packet filtering comprises two fundamental components: headers and payloads. These elements work together to regulate the flow of data packets within a network, playing a pivotal role in ensuring the safety and efficiency of digital communication.

Headers

In packet filtering, the examination of headers is a critical task. Headers contain vital information about each packet, including source and destination addresses, ports, and network protocol types. By analyzing these attributes, packet filters can make informed decisions on whether to allow or block packet transmission.

Payloads

While headers deal with the routing and control of data packets, payloads contain the actual data that the packet is transmitting. Packet filters may not delve as deeply into payload content as they do with headers, but they can still examine payload attributes for specific filtering purposes.

Types of Packet Filters

Dynamic Packet Filtering

Dynamic packet filtering is a type of firewall that dynamically adjusts its rule set based on the state of the network connections.

Static Packet Filtering

Static packet filtering employs a predetermined set of rules that do not change based on the state of network connections.

Stateful Packet Filtering

Stateful packet filtering combines the benefits of both dynamic and static filtering methods.

Stateless Packet Filtering

Stateless packet filtering operates based solely on the information available in the packet headers without considering the state of network connections.

Packet Filtering Use Cases

Packet-filtering firewalls find applications in various scenarios:

  1. Security Regulations without Authentication: Useful for limiting internal access between subnets and departments.
  2. First Line of Defense: Serving as the initial defense layer for many businesses.
  3. SOHO Networks with Budget Constraints: Favored for affordability in small networks.
  4. Isolating High-Risk Services: Configuring rules to allow only essential traffic to sensitive areas.
  5. Resource Conservation: Limiting or prioritizing specific types of traffic,
  6. Supporting Guest Networks: Managing and securing guest traffic.
  7. Compliance and Reporting: Aiding in compliance adherence and report generation.

Pros of Packet Filtering

Packet filtering boasts several advantages:

Cons of Packet Filtering

While packet filtering offers benefits, it also presents limitations:

FAQs

What does a packet filter do?

Regulates network access by scrutinizing inbound and outbound packets.

What is a packet filter vs a firewall?

A packet filter allows or blocks packets based on header information.

What is an example of packet filtering?

Implementing a rule that blocks a specific port, disabling services listening on that port.

Do I need packet filtering?

Enhances system performance and safeguards against external attacks, especially for LAN environments.