Firewalls and IDS/IPS
The Guards at the Gate
A network needs two kinds of protection: something that decides what may pass (a firewall) and something that watches for attacks and raises the alarm or steps in (an IDS or IPS). In this lesson you will learn what each does, how they differ and how their rules work.
Firewalls
A firewall filters traffic between networks, for example between the internet and your office, or between the staff zone and the server zone.
| Type | What it inspects | Notes |
|---|---|---|
| Packet filter | Source and destination IP, port, protocol | Fast and simple, but has no memory of connections |
| Stateful firewall | The above plus the state of each connection | Only allows replies to connections that were started from inside |
| Application / proxy firewall | The content of the application protocol | Can block specific web or email content |
| Next-generation firewall (NGFW) | Applications, users, malware and TLS traffic | Used by most banks and large companies today |
| Web application firewall (WAF) | HTTP requests to a website | Blocks SQL injection, XSS and bots in front of a web app |
Writing rules
Rules are read from the top and the first match wins. Always finish with a default deny.
1. ALLOW tcp any -> web-server 443
2. ALLOW tcp admin-subnet -> web-server 22
3. ALLOW tcp app-server -> db-server 3306
4. DENY any any -> any any (log)
Good habits: least privilege, comment every rule with who asked for it and why, log the denies, and review rules every quarter. Old "temporary" rules that nobody remembers are a leading cause of exposure.
IDS and IPS
- An IDS (Intrusion Detection System) watches traffic or hosts and alerts. It sits off to the side and cannot block.
- An IPS (Intrusion Prevention System) sits in line and can drop the malicious traffic automatically.
Where they run:
- Network-based (NIDS/NIPS): watches network traffic. Examples: Snort, Suricata, Zeek.
- Host-based (HIDS/HIPS): watches one machine: files, logins, processes. Examples: OSSEC/Wazuh.
How they detect
- Signature-based: matches known attack patterns. Accurate for known threats but blind to new ones.
- Anomaly-based: learns "normal" and flags differences. Can catch new attacks but produces more false alarms.
A simple Suricata/Snort style rule:
alert tcp any any -> $HOME_NET 22 (msg:"Possible SSH brute force";
flags:S; threshold:type both, track by_src, count 5, seconds 60; sid:1000001; rev:1;)
This says: raise an alert if one source sends 5 new SSH connection attempts within 60 seconds.
The alert problem
Every detection system produces false positives (harmless activity flagged) and false negatives (real attacks missed). Too many false positives cause alert fatigue, and analysts start ignoring alerts. Tuning rules is a constant job, and it is a big part of what a SOC analyst does (you will see this in Module 7).
Nigerian and Global Practice
Banks, telcos and fintechs in Nigeria typically combine an NGFW at the network edge, a WAF in front of internet banking and mobile apps, and an IDS/IPS plus a SIEM for monitoring, in line with the security expectations of regulators such as the Central Bank of Nigeria. Cloud teams worldwide use the same ideas through cloud firewalls (security groups), managed WAFs and cloud threat detection. Whatever the size, the layers are the same: filter, inspect, log, respond.
Limits to Remember
- Firewalls cannot see inside encrypted traffic unless they decrypt it.
- A firewall does nothing about a phishing email an employee opens or an attacker who already has valid credentials.
- An IPS can block legitimate traffic by mistake, so test in detect-only mode first.
Practice: Triage the Alerts
In the editor on the right, decide whether each IDS alert is a true positive (real threat) or a false positive (harmless). Notice how much context you need to decide.
Try it yourself
Key Takeaways
- Firewalls decide what may pass. Types include packet filter, stateful, application, next-generation and web application firewalls.
- Firewall rules are checked top to bottom and the first match wins. End with a default deny, log denies and review rules regularly.
- An IDS detects and alerts. An IPS sits in line and can block. Both can be network-based (Snort, Suricata) or host-based (Wazuh).
- Signature detection is accurate for known attacks. Anomaly detection can find new ones but has more false positives.
- False positives cause alert fatigue, so tuning is constant work. Firewalls and IDS cannot see inside encrypted traffic or stop phishing on their own.
Quick Quiz
1.What is the key difference between an IDS and an IPS?
2.Why is a stateful firewall better than a simple packet filter?
3.Analysts start ignoring alerts because most turn out to be harmless. What is this called and what is the remedy?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx