P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Security and edge

Firewall (NGFW): what it is and how it is attacked

Decides which connections are allowed between two networks.

Also known as

  • NGFW
  • packet filter

Typing any of them into the editor finds this object.

Why it matters on a security diagram

The rules on it are the actual boundary. What the diagram claims and what the firewall permits are often different.

How it gets attacked, and what reduces it

How it gets attacked

  • Rules added for a project and never removed
  • Management interface exposed to the internet

What reduces it

  • Review rules on a schedule and remove the ones added for finished projects
  • Keep the management interface off the internet entirely
  • Patch the appliance urgently, because flaws in the device itself are exploited within days of publication. Review the rules on their own schedule: both routes are live and neither has replaced the other

Where it sits

Group
Security and edge · The things that sit in front of something else and check what is trying to reach it.
Whose side, by default
Ours · Belongs to the organisation the diagram is about.
Catalogue identifier
firewall

Reviewed . CC BY 4.0.

Others in security and edge

The security and edge group lists all 11 of them side by side.

Firewall on your own diagram

Open the editor, press N, and type NGFW. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker