Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A network security engineer is configuring a new firewall rule to block all inbound traffic originating from a specific list of known malicious IP addresses. The rule needs to be applied at the earliest possible point in the traffic flow to minimize resource consumption and discard unwanted traffic quickly. At which layer of the OSI model does a traditional packet filtering firewall primarily operate to achieve this?

  1. AData Link Layer (Layer 2)
  2. BNetwork Layer (Layer 3)
  3. CApplication Layer (Layer 7)
  4. DTransport Layer (Layer 4)
Show answer & explanation

Correct answer: B. Network Layer (Layer 3)

A traditional packet filtering firewall primarily operates at the Network Layer (Layer 3) and Transport Layer (Layer 4) of the OSI model. For blocking based on source IP addresses, it operates at Layer 3.

Why the other options are wrong

  • A. Data Link Layer (Layer 2) firewalls or ACLs operate on MAC addresses, which is not the primary mechanism for blocking traffic from specific IP addresses.
  • C. Application Layer (Layer 7) firewalls inspect application-specific traffic, which is beyond basic IP address filtering.
  • D. Transport Layer (Layer 4) filtering involves port numbers (TCP/UDP), which is also part of traditional firewalls, but IP address filtering occurs at Layer 3.

OSI Model and Firewall Layers

The Open Systems Interconnection (OSI) model describes seven layers of computer networking, and firewalls operate at different layers depending on their functionality.

  • Packet filtering firewalls primarily operate at Layer 3 (Network) and Layer 4 (Transport).
  • Next-Generation Firewalls (NGFWs) inspect up to Layer 7 (Application).
  • Blocking by IP address occurs at Layer 3.

Memory trick: Firewalls guard gates at different levels of the network castle.

More Network Security questions