Skip to content

Designing firewall rule sets: zones, default deny, rule order and egress

How a firewall decides, and how to write rules that do what you intend: zones and a DMZ, deny by default, stateful filtering, first-match order and shadowed rules, outbound (egress) filtering, port forwards and their safer alternatives, and reading the log to find which rule matched a blocked connection.

Level
Intermediate
Length
About 50 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 3 Oct 2026

Skills you'll practise

  • Place systems in zones (including a DMZ for public services) and state what each zone may reach
  • Explain deny by default and stateful filtering, and what they mean for return traffic
  • Identify shadowed and over-broad rules in a first-match rule set and reorder or narrow them
  • Write outbound (egress) rules that limit what internal systems can reach
  • Use firewall log entries to find which rule matched a connection and decide on a fix

Course outline

  1. 1.Firewall rule sets that do what you meanVideo · 3 min
  2. 2.Zones, deny by default and stateLesson · 16 min
  3. 3.Rule order, shadowed rules and egressLesson · 17 min
  4. 4.Port forwards, logs and troubleshootingLesson · 16 min
  5. 5.Designing firewall rule sets: zones, default deny, rule order and egress: knowledge checkKnowledge check · 17 questions
  6. 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.