A firewall permits or denies network traffic using a set of rules called an access control list (ACL). Stateless firewalls filter based on packet header information only: IP address, port, and protocol. Stateful firewalls also track the state of active connections, allowing more precise control. Next-generation firewalls (NGFWs) add deep packet inspection, intrusion prevention, and application-layer filtering. ACL rules are checked in order and the first matching rule is applied, so rule order matters. Each network segment and each ingress or egress point between the internal network and the internet should have a firewall. A typical ACL rule specifies direction (inbound or outbound), filter criteria (IP, port, protocol, or application), and action (permit or deny). For example: Allow inbound TCP port 22 from ALL permits SSH traffic; Deny inbound TCP port 80 from 192.168.1.0/24 blocks HTTP from that subnet.
Given a set of ACL rules, can you trace a specific packet through the list and determine whether it is permitted or denied, and explain why rule order matters?