Designing firewall rule sets: zones, default deny, rule order and egress
How a firewall decides, and how to write rules that do what you intend: zones and a DMZ, deny by default, stateful filtering, first-match order and shadowed rules, outbound (egress) filtering, port forwards and their safer alternatives, and reading the log to find which rule matched a blocked connection.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Place systems in zones (including a DMZ for public services) and state what each zone may reach
- Explain deny by default and stateful filtering, and what they mean for return traffic
- Identify shadowed and over-broad rules in a first-match rule set and reorder or narrow them
- Write outbound (egress) rules that limit what internal systems can reach
- Use firewall log entries to find which rule matched a connection and decide on a fix
Course outline
- 1.Firewall rule sets that do what you meanVideo · 3 min
- 2.Zones, deny by default and stateLesson · 16 min
- 3.Rule order, shadowed rules and egressLesson · 17 min
- 4.Port forwards, logs and troubleshootingLesson · 16 min
- 5.Designing firewall rule sets: zones, default deny, rule order and egress: knowledge checkKnowledge check · 17 questions
- 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.