{"id":2493,"date":"2018-10-18T13:04:19","date_gmt":"2018-10-18T13:04:19","guid":{"rendered":"https:\/\/www.fastcomet.com\/blog\/?p=2493"},"modified":"2022-06-10T06:10:17","modified_gmt":"2022-06-10T06:10:17","slug":"firewall-the-first-layer-of-passive-defense-strategy","status":"publish","type":"post","link":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy","title":{"rendered":"Firewall, The First Layer of Passive Defense Strategy"},"content":{"rendered":"\n<p class=\"has-drop-cap\">As a natural continuation to our <a href=\"https:\/\/www.fastcomet.com\/blog\/security-hardening-essentials\" target=\"_blank\" rel=\"noopener noreferrer\">October\u2019s Cybersecurity thematic series<\/a>, this post\u2019s goal is to highlight all types of firewalls in existence, for both network appliance and server security management, along with their additional individual tricks of the trade.<\/p>\n\n\n\n<!--more-->\n\n\n\n<ul class=\"wp-block-list\"><li>Review our Series 1 \u2192 <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.fastcomet.com\/blog\/security-hardening-essentials\/\" target=\"_blank\">Security Hardening Essentials to Keep Your Site Safe<\/a><\/li><li>Review our Series 2 \u2192&nbsp;<a href=\"https:\/\/www.fastcomet.com\/blog\/content-security-policy-csp\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">An in-depth Dive into the World of the Content Security Policy (CSP)<\/a><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Bare Functionality<\/h2>\n\n\n\n<p>The firewall is one of the most commonly known pieces of software that guard our online presence. Its function is to filter out the traffic, so that no unauthorized devices are able to connect to the inner network, through the outer network, whilst still being able to control which devices are to be granted connection to, allowing the establishment of communication with applications and websites, thus still being able to utilize their online content.<\/p>\n\n\n\n<p>For years major companies over the world have depended on a large combination of software products in order to better their services and provide more functions and features to their clients, regardless of the company field of work. However, as time passes many of these companies have gone out of business, have ended their production and\/or support for the given products and this is where problems regularly start to arise.<\/p>\n\n\n\n<p>Security developers are no fools, they know that they cannot provide a solution to each case individually, but instead have to take a wider approach to things and craft creations such as the Firewall. There are several different types of firewalls, some of which are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li style=\"text-align: justify;\">A packet-filtering firewall which examines all isolated packets and is not aware of the packet\u2019s context;<\/li><li style=\"text-align: justify;\"><span style=\"font-weight: 400;\">A stateful inspection firewall examines network traffic and determines if a packet is related to another;<\/span><\/li><li style=\"text-align: justify;\">A proxy firewall inspects packets at the application layer of the Open Systems Interconnection (OSI) reference model;<\/li><li style=\"text-align: justify;\">An NGFW implements a multilayered method to integrate enterprise firewall capabilities with an intrusion prevention system (IPS) and application control.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The Importance of Having a Firewall Configuration<\/h2>\n\n\n\n<p>Security on an open network is becoming more and more important with each day. Following the growth of the Internet, the benefits of owning your own dedicated server can be felt on a global scale now. For many, their personal data and web service accessibility have become essential parts of their daily life routine. Having the benefit of accessibility leads to a service that is publicly available, making it wide open to unwanted and seemingly random connections.<\/p>\n\n\n\n<p>Often conducted with the use of bots and spoofed IP addresses, it\u2019s common on the open Internet to experience foreign login attempts, port scans, in addition to other intrusive activity. There are basic security and firewall methods that can help in the prevention of these activities from turning into a much more alarming issue.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">External Security Measures<\/h2>\n\n\n\n<p>A great example for such a 3rd party defense would be <a href=\"https:\/\/www.fastcomet.com\/blog\/fastcomet-certified-cloudflare-hosting-partner\" target=\"_blank\" rel=\"noopener noreferrer\">Cloudflare\u2019s DDoS protection services<\/a>, which after applied includes features like browser integrity checking, which involves validating the user agent of the browser, as well as the IP address of the connecting side. That way, it can distinguish an actual user trying to connect to the website and deny connection to any other non-authentical traffic generating type events.<\/p>\n\n\n\n<p>Cloudflare also has a built-in web application firewall (WAF) which is extremely hard to bypass even to the more sophisticated of attackers. It filters traffic by allowing only browser type user agents to connect to your website, as any other type would be malicious. It also monitors ongoing connections and notifies the administrative contact of a website if it establishes that anything out of the ordinary starts occurring.<\/p>\n\n\n\n<p>By default, it will close any ports which are not in use, and you can limit which IP addresses can connect to certain open ports as well, for example, ports 2082 and 2083 for cPanel, making it so that only the administrator\u2019s IP can even access the page, and refusing connection for any other connection attempts, providing you a very secure solution for your administration page.<\/p>\n\n\n\n<p>In the unlikely event that somehow an attacker does manage to pass the above walls of security, the Cloudflare rate-limiting function will only allow them a few user-chosen amounts of login attempts after being put down into an on-lock mode. Afterward, a confirmation will be requested on the administrator\u2019s email before being able to try and log in again.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Standard Network Firewall vs Web Application Firewall (WAF)<\/h2>\n\n\n\n<p>The core difference between these two is their basic functionality and appliance. The standard firewall only provides your internal network with the most basic traffic filtering options. Web Application Firewall (WAF) protects all your internet properties from commonly seen vulnerabilities such as cross-website online scripting (XSS) and cross-website online forgery requests (CSRF).<\/p>\n\n\n\n<p>It also stops Brute force login attempts, SQL Injections, DDoS\/DoS attacks, and many other of the major cybersecurity types of attacks listed in the top Open Web Application Security Project (OWASP) vulnerability list.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Breadwinners<\/h2>\n\n\n\n<p>When it comes to making our choice onto which Web Application Firewall (WAF) we will actively deploy to our server, the list of options certainly won\u2019t fit a single page. In the FastComet server environment, our main layers of defense consist of <strong>ModSecurity<\/strong> and <strong>BitNinja<\/strong>.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.fastcomet.com\/blog\/implementing-new-modsecurity-rules-against-malware\" target=\"_blank\" rel=\"noopener noreferrer\">ModSecurity<\/a> is a special security ruleset, which over time has amassed a large pool of additional features and is now a crowd favorite option. It comes pre-installed on most of the management panels, such as cPanel\/WHM and Plesk. It does its job extremely well, providing quality defense for both the server modules, operating system and installed applications themselves.<\/p>\n\n\n\n<p>FastComet is also in a partnership with the 3rd party services provider <a href=\"https:\/\/www.fastcomet.com\/blog\/introducing-bitninja-partnership\" target=\"_blank\" rel=\"noopener noreferrer\">BitNinja<\/a>. The main focus of their product is to further strengthen the already present security setup of a server, adding the missing elements that may be found lacking. Once applied, the minimum ruleset you can set on your BitNinja settings prevents the following methods of exploitation.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li style=\"text-align: justify;\">Web application vulnerability scanners<\/li><li style=\"text-align: justify;\">Port scans<\/li><li style=\"text-align: justify;\">Protocol attacks (loss of service)<\/li><li style=\"text-align: justify;\">Remote code execution<\/li><li style=\"text-align: justify;\">Code modification<\/li><li style=\"text-align: justify;\">Remote File Inclusion<\/li><li style=\"text-align: justify;\">PHP General Attacks<\/li><li style=\"text-align: justify;\">Operating system version disclosure<\/li><li style=\"text-align: justify;\">Blocks high-risk characters<\/li><\/ul>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><a href=\"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy\/infographic-how-bitninja-protects-your-website\/\"><img loading=\"lazy\" decoding=\"async\" width=\"2480\" height=\"3508\" src=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/Infographic-how-bitninja-protects-your-website.jpg\" alt=\"Infographic: How BitNinja protects your website\" class=\"wp-image-2501\" srcset=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/Infographic-how-bitninja-protects-your-website.jpg 2480w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/Infographic-how-bitninja-protects-your-website-212x300.jpg 212w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/Infographic-how-bitninja-protects-your-website-768x1086.jpg 768w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/Infographic-how-bitninja-protects-your-website-724x1024.jpg 724w\" sizes=\"auto, (max-width: 2480px) 100vw, 2480px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>While there will always be new ways to bend the rules and thousands of exploits are discovered on a monthly basis, a well established first line of defense will most certainly guarantee us a certain peace of mind that our content won\u2019t fall into the hands of the general public.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As a natural continuation to our October\u2019s Cybersecurity thematic series, this post\u2019s goal is to highlight all types of firewalls in existence, for both network appliance and server security management, along with their additional individual tricks of the trade.<\/p>\n","protected":false},"author":11,"featured_media":2490,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[140],"tags":[109,9],"class_list":["post-2493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-bitninja","tag-security"],"featured_image_src":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg","author_info":{"display_name":"Daniel G.","author_link":"https:\/\/www.fastcomet.com\/blog\/author\/danielg"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Firewall, The First Layer of Passive Defense Strategy | FastComet<\/title>\n<meta name=\"description\" content=\"Cybersecurity threats are multiplying. ? Check our post on what is a Firewall and why is it important for network security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Firewall, The First Layer of Passive Defense Strategy | FastComet\" \/>\n<meta property=\"og:description\" content=\"Cybersecurity threats are multiplying. ? Check our post on what is a Firewall and why is it important for network security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy\" \/>\n<meta property=\"og:site_name\" content=\"FastComet Blog\" \/>\n<meta property=\"article:published_time\" content=\"2018-10-18T13:04:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-10T06:10:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Daniel G.\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel G.\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Firewall, The First Layer of Passive Defense Strategy | FastComet","description":"Cybersecurity threats are multiplying. ? Check our post on what is a Firewall and why is it important for network security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy","og_locale":"en_US","og_type":"article","og_title":"Firewall, The First Layer of Passive Defense Strategy | FastComet","og_description":"Cybersecurity threats are multiplying. ? Check our post on what is a Firewall and why is it important for network security.","og_url":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy","og_site_name":"FastComet Blog","article_published_time":"2018-10-18T13:04:19+00:00","article_modified_time":"2022-06-10T06:10:17+00:00","og_image":[{"width":1024,"height":620,"url":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg","type":"image\/jpeg"}],"author":"Daniel G.","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel G.","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#article","isPartOf":{"@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy"},"author":{"name":"Daniel G.","@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/206e275441cf4ae1dd16d0c63107f0a2"},"headline":"Firewall, The First Layer of Passive Defense Strategy","datePublished":"2018-10-18T13:04:19+00:00","dateModified":"2022-06-10T06:10:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy"},"wordCount":1080,"commentCount":1,"image":{"@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#primaryimage"},"thumbnailUrl":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg","keywords":["bitninja","security"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy","url":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy","name":"Firewall, The First Layer of Passive Defense Strategy | FastComet","isPartOf":{"@id":"https:\/\/www.fastcomet.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#primaryimage"},"image":{"@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#primaryimage"},"thumbnailUrl":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg","datePublished":"2018-10-18T13:04:19+00:00","dateModified":"2022-06-10T06:10:17+00:00","author":{"@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/206e275441cf4ae1dd16d0c63107f0a2"},"description":"Cybersecurity threats are multiplying. ? Check our post on what is a Firewall and why is it important for network security.","breadcrumb":{"@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#primaryimage","url":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg","contentUrl":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2018\/10\/firewall.jpg","width":1024,"height":620},{"@type":"BreadcrumbList","@id":"https:\/\/www.fastcomet.com\/blog\/firewall-the-first-layer-of-passive-defense-strategy#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.fastcomet.com\/blog"},{"@type":"ListItem","position":2,"name":"Firewall, The First Layer of Passive Defense Strategy"}]},{"@type":"WebSite","@id":"https:\/\/www.fastcomet.com\/blog\/#website","url":"https:\/\/www.fastcomet.com\/blog\/","name":"FastComet Blog","description":"FastComet Web Hosting Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.fastcomet.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/206e275441cf4ae1dd16d0c63107f0a2","name":"Daniel G.","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/80f7a08d4fd8c78380c04d41c47e6e07ac71e66c022d2fd93e32dcd8e3879e16?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/80f7a08d4fd8c78380c04d41c47e6e07ac71e66c022d2fd93e32dcd8e3879e16?s=96&d=mm&r=g","caption":"Daniel G."},"description":"Daniel works in Customer Success at FastComet. A self-described 'massive geek' and cybersecurity enthusiast, Daniel draws on his skills to research, understand, and disseminate Performance Monitoring complex topics to reach FastComet's technical audience.","sameAs":["https:\/\/www.fastcomet.com\/"],"url":"https:\/\/www.fastcomet.com\/blog\/author\/danielg"}]}},"_links":{"self":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts\/2493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/comments?post=2493"}],"version-history":[{"count":12,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts\/2493\/revisions"}],"predecessor-version":[{"id":7856,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts\/2493\/revisions\/7856"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/media\/2490"}],"wp:attachment":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/media?parent=2493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/categories?post=2493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/tags?post=2493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}