Firewall Rule Lab
Firewalls fail on order and specificity, not syntax. Build an ordered allow/deny ruleset, replay a set of labelled packets through it first-match-wins, and watch the lab flag the two mistakes that cause real outages and exposures: rules that are shadowed (never fire) and rules that are too broad (any→any allow). Hit the goal — block the threat, keep the business traffic — and you pass.
Goal
Let normal business traffic out, allow inbound only to the DMZ web server, and block the C2 beacon and the RDP exposure. The last rule is an implicit default-deny.
Ruleset (top-down, first match wins)
Score vs goal
Edit the rules, then replay to grade them.
Legend
Amber rule — shadowed (never fires).
Red rule — any→any allow (too broad).
Hit counters show how many of the replayed packets each rule actually matched first.
Live now
4 on this scenariored team is loading probes…
What this lab is
- A free, browser-based firewall lab: write an ordered allow/deny ruleset and replay labelled packets through it like a real packet filter.
- Rules are evaluated top-down, first match wins, with an implicit default-deny tail — the model every stateless firewall actually uses.
- The lab flags shadowed rules (an earlier rule already covers them so they never fire) and overly broad any→any ALLOW rules.
- Each scenario has a goal — block the C2 beacon, keep business traffic, segment the OT network — and you are scored on threats blocked vs. business flows kept.
- Per-rule hit counters and a per-packet first-match trace show exactly why each packet was allowed or denied.
Frequently asked questions
What is the Firewall Rule Lab?
A free, in-browser exercise where you build an ordered firewall ruleset (source zone, destination zone, port, protocol, allow/deny) and replay a set of labelled packets through it. Rules are matched top-down, first match wins, with an implicit default-deny at the end — the same evaluation model as a stateless packet filter or a cloud security-group/NACL. You see which rule matched each packet and whether the result met the scenario goal.
What are shadowed and overly-broad rules?
A shadowed rule is one that never fires because an earlier, same-or-broader rule already matches every packet it would. It is dead config that hides intent and causes drift. An overly-broad rule is an any→any ALLOW: it permits everything beneath the first match and is a classic cause of unintended exposure. The lab highlights both as you edit.
Who is it for?
Analysts and engineers learning firewall, security-group and NACL rule ordering, people prepping for a network-security or cloud interview, and anyone who wants to feel why rule order and default-deny matter without touching production. No account or install.
Is this a real firewall?
No. It is a teaching model of first-match-wins evaluation with a default-deny tail. It deliberately ignores stateful connection tracking, NAT and deep inspection so the one lesson — ordering, specificity and default-deny — is clear. The scenarios and packets are invented.