Skip to content
Educora
Intermediate18 min5 / 12

Network security: ports, firewalls, VPNs and Wi-Fi

Understand the attack surface through ports, write firewall rules, choose VPN and Wi-Fi protection, and learn the defences against MITM, DNS spoofing and DDoS attacks.

Check yourself
In this lesson you will learn
  • Treat open ports as attack surface and close the unnecessary ones
  • Build firewall rules on the “first match wins” principle
  • Know what VPNs and Wi-Fi standards do and do not protect against
  • Recognise MITM, DNS spoofing and DDoS and choose defences

Murad set up a small web server at home for the school club. The next morning the log showed thousands of connection attempts on ports 22 and 3389 from addresses he had never seen. Nobody had picked him as a target: scanners probe the whole internet non-stop. In this lesson we learn how to defend a network.

Ports and the attack surface

An IP address is like a building and a port like a door number (0–65535). Behind every open port a service is running, and every service is a potential way in. The sum of all entry points reachable from outside is called the attack surface. The golden rule: close everything you do not need.

PortServiceRecommendation
22SSHonly via VPN or allow-listed addresses; keys instead of passwords
23Telnetunencrypted — switch it off
80HTTPonly to redirect to HTTPS
443HTTPSopen for a public website
3306MySQLmust never be open to the internet
3389RDPnever directly on the internet, only behind a VPN

Firewalls

A firewall filters traffic by rules: direction, protocol, port, source and destination address. Rules are checked from top to bottom, the first matching rule wins, and the last rule is “deny everything else”. A stateful firewall remembers established connections, so replies to requests you sent get through without extra rules.

Python
import ipaddress

RULES = [
    ('allow', 'tcp', 443, '0.0.0.0/0'),     # HTTPS from anywhere
    ('allow', 'tcp', 22, '10.0.0.0/24'),    # SSH only from the office LAN
    ('deny', 'any', None, '0.0.0.0/0'),     # everything else
]

def decide(proto, port, src):
    for action, r_proto, r_port, r_net in RULES:
        if r_proto not in ('any', proto):
            continue
        if r_port is not None and r_port != port:
            continue
        if ipaddress.ip_address(src) in ipaddress.ip_network(r_net):
            return action
    return 'deny'

for packet in [('tcp', 443, '203.0.113.7'), ('tcp', 22, '10.0.0.15'),
               ('tcp', 22, '203.0.113.7'), ('tcp', 3306, '10.0.0.15')]:
    print(packet, '->', decide(*packet))
▸ Expected output
('tcp', 443, '203.0.113.7') -> allow
('tcp', 22, '10.0.0.15') -> allow
('tcp', 22, '203.0.113.7') -> deny
('tcp', 3306, '10.0.0.15') -> deny
A tiny firewall model. 203.0.113.x addresses are reserved for documentation examples, and 10.0.0.0/24 is the internal office network.

VPNs and Wi-Fi

A VPN builds an encrypted tunnel between your device and a VPN server (or a company network): it protects traffic on an untrusted network and gives remote access to internal resources. But a VPN does not make you anonymous and does not protect you from phishing or malware; it simply moves your trust from the internet provider to the VPN service. Modern protocols: WireGuard, IPsec, OpenVPN.

Wi-Fi modeVerdict
Open networkthe radio link is not encrypted — only with HTTPS and a VPN
WEPbroken long ago, never use it
WPA2 (AES)acceptable with a long passphrase
WPA3 (SAE)best: resists offline password guessing
On a home router, also change the admin password, update the firmware, switch off WPS and create a separate guest network for visitors and smart devices.

In larger networks another key technique is segmentation: the network is split into separate zones (office computers, servers, cameras, guests), and only the traffic that is really needed may cross between zones. Even if a camera is hijacked, the attacker cannot jump from it to the accounting server. At zone borders, IDS/IPS systems detect or block suspicious traffic.

Common attacks and defences

AttackThe ideaDefence
Man-in-the-middle (MITM)the attacker slips between you and the site, for example with a fake “Free_WiFi” hotspot, and reads or alters the trafficHTTPS and HSTS, taking certificate warnings seriously, a VPN on public networks
DNS spoofinga DNS resolver receives a forged answer, so the domain points to the attacker's IPDNSSEC, encrypted DNS (DoH, DoT), a trusted resolver; TLS certificate checks expose the fake site
DDoSthousands of hijacked devices (a botnet) flood a service with requestsCDNs and scrubbing services, rate limiting, spare capacity, a plan agreed with the provider
Example: why can't you stop a DDoS on your own server?

The school's internet link is 1 Gbit/s. A botnet has 10,000 devices, each sending 2 Mbit/s. How many times is the link overloaded?

Show solution
Total traffic: 10,000 · 2 Mbit/s = 20,000 Mbit/s = 20 Gbit/s.
Ratio: 20 Gbit/s ÷ 1 Gbit/s = 20 times.
Conclusion: the link is full before packets even reach the server, so a firewall on the server does not help. Filtering must happen upstream — at the provider or a CDN.
Exercise

The office computers cannot reach the DNS server (UDP, port 53). Add a rule to RULES that allows UDP 53 only from the 10.0.0.0/24 network. Put the rule in the right place so that the output is allow, deny, deny.

Exercise · Python
import ipaddress

RULES = [
    ('allow', 'tcp', 443, '0.0.0.0/0'),
    ('allow', 'tcp', 22, '10.0.0.0/24'),
    ('deny', 'any', None, '0.0.0.0/0'),
]
# add a rule for DNS: udp, port 53, office LAN only

def decide(proto, port, src):
    for action, r_proto, r_port, r_net in RULES:
        if r_proto not in ('any', proto):
            continue
        if r_port is not None and r_port != port:
            continue
        if ipaddress.ip_address(src) in ipaddress.ip_network(r_net):
            return action
    return 'deny'

print(decide('udp', 53, '10.0.0.15'))
print(decide('udp', 53, '198.51.100.4'))
print(decide('tcp', 23, '10.0.0.15'))
▸ Expected output
allow
deny
deny

Key points

  • Every open port is part of the attack surface; close the ones you don't need and never expose management ports to the internet.
  • Firewall rules are checked top to bottom, the first match wins, and “deny everything” comes last.
  • A VPN protects traffic inside a tunnel but gives no anonymity and no protection from phishing.
  • For Wi-Fi, WPA3 is best, WPA2 is acceptable with a long passphrase and WEP is useless.
  • HTTPS and certificate checks defeat MITM, DNSSEC fights DNS spoofing, and upstream filtering handles DDoS.

Check yourself

10 questions. Every correct answer earns XP.

1 / 10
Which port is especially dangerous to expose directly to the internet?