Network Foundations

A track of P58 · Cloud & Network Security.

What can reach a service at all — first-match firewall rules with default deny, and classifying exposure as loopback, private or public from a binding.

A developer starts a database for local work. The default configuration binds it to 127.0.0.1; a tutorial suggests 0.0.0.0 so that a container can reach it, and it works, so the line stays. Later that machine gets a public address, or the container moves to a cloud host with a permissive default group. Nothing was attacked and no code was vulnerable — the database is simply now reachable by the internet, with whatever authentication it happened to have. Exposure is decided by configuration nobody reads, and this track makes it something you can read on purpose.

It starts with the binding, because that single value determines who can even open a socket to your service. Loopback means only this machine. A private interface address means whatever else is on that network segment, which may be one container or an entire office. 0.0.0.0 means every interface the host has, including ones it may acquire later. You will practise classifying a service as loopback, private or public from its configuration, which sounds elementary until you do it against a realistic setup and find that the answer depends on facts that live in three different places.

Then the rule set that filters what the binding allows. Firewall rules are evaluated in order and the first match wins, which makes the ordering load-bearing in a way that reading the rules as a set does not capture: a broad allow placed above a specific deny renders the deny dead, and the rule set still looks correct. Underneath it all sits the default policy, and default deny is the only choice that fails safely — with default allow, every service you forget to consider is exposed, whereas with default deny the failure mode is a connection refused and a quick fix. You will evaluate rule sets against traffic and predict the verdict before checking, which is the skill that makes a review worth anything.

Bindloopback, private, or publicFilterrules in order, first match winsDefault denyforgetting fails closedClassifyread exposure off the config
The cheapest control in the discipline: what can reach the service at all, decided deliberately.
Network Foundations — TransformerLab