Learning Hub › Foundational Security › Network Security 101
Foundations 02 · Interactive guide
Network Security 101
Every attack crosses a network at some point. This guide explains how traffic is structured (layers, ports, packets), then puts you in charge of the tools that control and watch it: a firewall you configure yourself and an IDS/IPS you can switch between modes.
The layers: OSI and TCP/IP
Networking is built in layers, each relying on the one below. The 7-layer OSI model is the vocabulary security people use ("a layer-7 attack"); the 4-layer TCP/IP model is what the internet actually runs. Click a layer to see what lives there and how it gets attacked.
Ports and the TCP handshake
An IP address finds the machine; a port finds the service on it (0–65535). Many old protocols send everything in clear text, and each has a secure replacement. Attackers scan for open ports first, so every open port is part of your attack surface.
TCP three-way handshake
Press Connect to open a TCP connection to a web server on port 443.
Firewall lab: fix the rule base
A firewall checks each packet against an ordered list of rules. The first matching rule wins, and anything that matches nothing hits the implicit deny at the bottom. One badly placed "allow any" rule silently opens everything below it.
Rule base (top to bottom)
Test traffic
Packet filter
Looks at each packet's addresses, ports and protocol. Fast, but has no memory of conversations.
Stateful firewall
Tracks connections, so replies to your outbound requests are allowed back in automatically. The standard today.
Next-gen firewall / WAF
Understands applications and users (layer 7). A web application firewall inspects HTTP for attacks like SQL injection.
IDS vs IPS: watch or block?
An intrusion detection system watches a copy of the traffic and raises alerts. An intrusion prevention system sits inline and can drop bad packets, at the cost that its mistakes block real users. Each detects with signatures (known patterns) or anomalies (unusual behaviour). Switch the mode and send traffic.
Send traffic
What a signature looks like (Suricata syntax, simplified sample)
alert http any any -> $HOME_NET any ( msg:"Possible SQL injection - UNION SELECT"; flow:to_server,established; http.uri; content:"union"; nocase; content:"select"; nocase; distance:0; classtype:web-application-attack; sid:1000001; rev:1; )
Packet anatomy: what Wireshark shows you
Each layer wraps the data from the layer above with its own header, like envelopes inside envelopes. Click any field to see what it means and why defenders care. Then flip to HTTPS and see what an eavesdropper loses.
Myth or fact?
Five things people often get wrong about network defences.
Sources & further reading
- NIST SP 800-41 Rev. 1: Guidelines on Firewalls and Firewall Policy
Firewall types, rule-base design and the default-deny principle.
- NIST SP 800-94: Guide to Intrusion Detection and Prevention Systems
IDPS types, detection methods and deployment.
- RFC 9293: Transmission Control Protocol
The 2022 consolidated TCP specification, including the handshake. IPv4 is RFC 791.
- IANA Service Name and Port Number Registry
The official list of well-known ports.
- Suricata rule documentation
How open-source IDS/IPS signatures are written.
- Wireshark User's Guide
The free tool for capturing and reading packets yourself.
Next: see why perimeter firewalls are not enough on their own in the Zero Trust deep dive, and how TLS keeps packets private in Cryptography Basics.