Computer security: networks, firewalls, and ports
Learning intentions
You will learn:
- What a computer network is and why it needs protecting
- How different measures help keep a network secure
- How firewalls control network traffic
- What network ports are and how firewalls use them
- How multiple layers of protection work together in a school network
Network security
What is a network?
A computer network is a group of two or more connected computing devices. Networks can range from small personal or local networks to large wide-area networks connecting many locations.
- PAN (Personal Area Network): connects personal devices over a short distance.
- LAN (Local Area Network): connects devices in a limited area such as a home, school, or office.
- WAN (Wide Area Network): connects smaller networks across large distances.
What is network security?
Network security is the collection of technologies and practices used to protect networks from attacks, unauthorised access, and data breaches.
Common network security risks
- Unauthorised access: Someone gains access to information or systems they are not permitted to use.
- DDoS attacks: Attackers flood a network or server with unwanted traffic so legitimate users cannot use it.
- Vulnerability exploits: Attackers take advantage of weaknesses in software, hardware, applications, or login systems.
- Malware: Malicious software such as ransomware, worms, and spyware can damage systems, steal information, or spread through a network.
- Insider threats: Authorised users may accidentally or deliberately compromise security.
Security measures
- Access control determines which users are allowed to access particular data, applications, or systems.
- Authentication verifies a user’s identity. Two-factor authentication (2FA) improves security by requiring an additional form of verification beyond a password.
- Firewalls inspect network traffic and block traffic that violates security rules.
- DDoS protection attempts to keep services available when attackers send extremely large amounts of unwanted traffic.
- Data loss prevention measures help prevent sensitive information from being taken outside an organisation’s network.
- Backups provide additional copies of important information so data can be restored after attacks, equipment failures, or accidental deletion.
- Users can accidentally create security problems by opening unsafe attachments, entering credentials into phishing sites, or allowing unauthorised access. Security education helps reduce these risks.
- Zero Trust is based on the principle that users and devices should not automatically be trusted. Access requests should be verified.
Firewalls
What is a firewall?
A firewall is a security system that monitors and controls network traffic using a set of rules.
A firewall often sits between a trusted network, such as a school network, and an untrusted network, such as the Internet.
It decides whether incoming and outgoing traffic should be allowed or blocked.
Why use a firewall?
A firewall can:
- stop malicious incoming traffic before it reaches devices;
- restrict unwanted connections;
- help prevent sensitive information leaving a network;
- control access to particular websites or services.
The name comes from physical firewalls in buildings, which help stop fire spreading between areas. A network firewall similarly creates a controlled barrier between networks.
Firewall rules
Firewall rules can consider information such as:
- source IP address;
- destination IP address;
- network port;
- type of traffic;
- application;
- user or device identity.
For example, a firewall could permit normal web traffic while blocking connections to network services that should not be accessible from the Internet.
Firewall types
A proxy-based firewall sits between a client and a server. The client connects to the firewall, which inspects the traffic and then creates a separate connection to the destination if it is allowed.
This prevents a direct connection between client and server, although the additional inspection can introduce delays.
Stateful firewall
A stateful firewall remembers information about active connections. It can use information about earlier traffic to decide whether new incoming or outgoing traffic makes sense.
For example, after a computer sends a legitimate request, the firewall can recognise and allow the expected response.
Next-generation firewall
A next-generation firewall (NGFW) adds features such as:
- Deep packet inspection: examines packet contents more thoroughly.
- Application awareness: identifies applications generating traffic.
- Identity awareness: can apply rules according to users or devices.
- Sandboxing: isolates suspicious code so its behaviour can be examined.
Web Application Firewall
A Web Application Firewall (WAF) specifically protects web applications by monitoring HTTP traffic between the application and the Internet.
Cloud firewall
Firewalls do not have to be physical devices. They can run as software or operate as cloud services.
Network ports
What is a network port?
A network port is a numbered virtual endpoint used to direct network communications to the correct application or service.
It is not a physical socket.
A useful analogy is:
- IP address = building address
- Port = particular door or room
The IP address directs traffic to the correct network location. The port helps direct it to the correct service.
Port numbers range from 0 to 65535.
Common ports
| Port | Service | Common use |
|---|---|---|
| 20/21 | FTP | File Transfer Protocol, for sharing files |
| 22 | SSH | Secure Shell, for accessing a computer’s shell remotely |
| 25 | SMTP | Simple Mailbox Transfer Protocol, for sending emails |
| 53 | DNS | Domain Name Server, for domain-name lookup |
| 80 | HTTP | Hypertext Transfer Protocol, for serving web sites and other web traffic |
| 443 | HTTPS | Hypertext Transfer Protocol Secured, for encrypted web traffic |
These are standard associations, although applications can sometimes use different ports.
Allowing and blocking ports
Firewalls can allow or block traffic based on port numbers.
For example, a server providing a secure website may need port 443 available but may not need many other ports exposed to the Internet.
Open and closed ports
- An open port is accepting connections.
- A closed port is not accepting connections.
Open ports are not automatically unsafe because legitimate network services need them. However, unnecessary exposed services can increase security risk.
Port scanning
Port scanning involves testing ports on a computer or network to discover which ones are accessible.
An attacker may use this information to identify running services and then search for weaknesses in them. Firewalls can reduce this risk by blocking unwanted connections.
Virtual Local Area Networks
What is a VLAN?
A VLAN (Virtual Local Area Network) divides a physical network into separate logical networks. Devices can share the same switches and cabling while belonging to different groups.
Each VLAN has its own broadcast domain: a message sent to all devices in one VLAN stays within that VLAN. Switches do not directly forward this traffic into another VLAN.
Network administrators assign switch ports to VLANs through configuration. This means devices can be grouped by their purpose or users, even when they are in different rooms or buildings.
How could a school use VLANs?
Cisco’s school network design guide describes assigning different VLANs and traffic policies to administrators, teachers, and students.
This separates groups with different access needs. Being connected to the same school network does not have to give every device the same access.
Communicating between VLANs
Traffic between VLANs needs routing, provided by a router or a Layer 3 switch (a switch that can also route traffic).
Access control lists (ACLs) are rules that permit or deny traffic. Administrators can apply these rules to restrict communication between VLANs while allowing necessary connections.
For example, applying Cisco’s access-control approach to a school, rules could allow students to reach a learning server while blocking connections to administration computers. This is an illustrative application of the source’s principles.
How do VLANs protect a school?
- Separation: devices in different groups do not share one local broadcast domain.
- Controlled access: rules between VLANs can prevent one group from reaching another group’s protected systems.
- Necessary communication: routing can still allow access to approved shared services.
Creating VLANs alone does not decide which routed connections are safe. If routing allows all traffic between them, the intended access restrictions are missing. Protection depends on configuring the VLANs and the rules between them correctly.
Putting it together
Protecting a school network
Consider a school network containing student devices, teacher computers, printers, servers, and Internet-connected services.
The school could improve security by:
- authenticating users;
- controlling which resources different users can access;
- using firewalls to control incoming and outgoing traffic;
- exposing only necessary network ports;
- protecting against malware and DDoS attacks;
- maintaining backups;
- educating users about phishing and other threats.
Network security therefore uses multiple layers of protection rather than relying on one security technology.
Key vocabulary
| Term | Meaning |
|---|---|
| Network | Two or more connected computing devices |
| Network security | Technologies and practices used to protect networks |
| Firewall | A system that controls network traffic according to security rules |
| Authentication | Verifying the identity of a user or device |
| Access control | Deciding what resources a user or device may access |
| Malware | Software designed to cause harm or unwanted actions |
| DDoS | An attack that overwhelms a service with unwanted traffic |
| IP address | An address identifying a location or device on a network |
| Port | A numbered virtual endpoint used to direct network traffic |
| Port scanning | Testing ports to discover accessible network services |
| Packet | A unit of data transmitted across a network |
| Zero Trust | An approach in which access is verified rather than automatically trusted |
Sources
This summary is based on the following resources, which you can consult for further study:
- What is network security? • Cloudflare
- What is a firewall? • Cloudflare
- What is a computer port? • Cloudflare
- Configuring Routing Between VLANs • Cisco — VLAN separation, broadcast domains, and grouping devices.
- Configure Inter-VLAN Routing with Catalyst Switches • Cisco — routing between VLANs and restricting access with ACLs.
- Access Layer Security Design: School Network Design Guide • Cisco — separate VLANs and traffic policies for administrators, teachers, and students.