Network security isn't about any single product. It's a set of principles for controlling what traffic is allowed to go where, who is allowed to do what, and for catching it when something goes wrong anyway. This lesson covers the foundational concepts that everything else in network security builds on. The next three lessons then put them into practice: Firewall basics, VPN basics and Network segmentation.
💡 In simple terms: think of an office building. Doors with locks keep strangers out. Staff badges prove who you are and open only the rooms you need. Sealed envelopes keep letters private. Cameras record who went where. Network security uses the same ideas, just for data.
What network security is, and why it exists
Network security is everything done to protect a network and the data that travels across it from being read, changed, misused or stopped by people who shouldn't. It is needed because networks were originally built to deliver traffic, not to question it. A router forwards any packet it has a route for; a switch delivers any frame to the right port. Early protocols such as Telnet, FTP and HTTP even sent passwords as plain text. Security was added later, in layers.
Security sits everywhere in the network: on each device (passwords, updates, host firewalls), at the boundaries between networks (firewalls), on the links (encryption), and in the people and processes (training, logging, access reviews).
The CIA triad: what is being protected
Security people describe their goals with three words, known as the CIA triad. (Nothing to do with the intelligence agency.) Every attack harms at least one of them, and every defence protects at least one.
🔒 Confidentiality
Only the right people can read the data. A stranger on café Wi-Fi must not be able to read your email or passwords.
Protected by: Encryption, access control, MFA
✅ Integrity
Data is not changed, by accident or on purpose, without anyone noticing. A bank transfer of €100 must not become €10,000 on the way.
Protected by: Hashes and integrity checks, digital signatures, change logs
🟢 Availability
Systems and data are there when people need them. The online shop must stay up during the sale.
Protected by: Redundant links and devices, backups, DoS protection
The three pull against each other. A system locked in a safe with no network is very confidential but not very available. Good security is about the right balance for each system: a public website needs availability and integrity more than confidentiality; a payroll database needs all three.
AAA: who gets in, what they can do, and what they did
Controlling access to networks and devices follows three steps, known as AAA:
| Step | Question it answers | Example |
|---|---|---|
| Authentication | Who are you? Prove it. | Ana signs in to the Wi-Fi with her username, password and a phone prompt |
| Authorization | What are you allowed to do? | Ana is in the Finance group, so she may reach the accounts server but not the switch admin pages |
| Accounting | What did you do, and when? | A log records that Ana connected at 09:02 from 192.168.10.23 and disconnected at 17:31 |
In a business, these checks usually happen on a central AAA server rather than on each device. Wi-Fi access points, VPN gateways and switches all ask the same server, so a user's account can be disabled in one place. The most common protocol for this is RADIUS (UDP ports 1812 for authentication and 1813 for accounting). For logging in to network devices themselves, TACACS+ (TCP 49) is also common.
Authentication factors and MFA
There are three kinds of proof, called factors:
Something you know
A password or PIN. Easy to steal through phishing, guessing or reuse on another site.
Something you have
A phone with an authenticator app, a hardware security key, a smart card.
Something you are
A fingerprint or face scan, usually used to unlock the device that holds the key.
Multi-factor authentication (MFA) requires two or more different kinds. A password plus a code from a phone app is MFA; two passwords are not. MFA matters because stolen passwords are the most common way in: with MFA, a phished password alone is not enough. Hardware security keys and passkeys are the strongest options, because they also refuse to work on a fake website.
⚠️ Attackers sometimes send dozens of MFA push prompts hoping the user taps "Approve" to make them stop. Never approve a sign-in you didn't start.
Least privilege
The principle of least privilege says every person, device and program should have only the access it needs to do its job, and no more. It applies at every level:
- User accounts: staff use normal accounts day to day; admin rights are separate and used only when needed.
- Network access: a firewall rule allows the reception PC to reach the booking server on one port, not "anything, anywhere".
- Devices: a printer has no reason to reach the payroll database, so it can't.
- Time: a contractor's VPN account expires when the contract does.
Least privilege limits damage. If an account or device is compromised, the attacker only gets what that account could do. It is the idea behind the implicit deny in Firewall basics and behind Network segmentation.
Encryption: keeping data private and unchanged
Encryption scrambles data with a secret key so that only someone with the right key can read it. Readable data is called plaintext; scrambled data is ciphertext. Modern encryption also adds an integrity check, so any change to the ciphertext is detected.
Encryption in transit
Protects data while it crosses a network. Examples: HTTPS (TLS) for websites, SSH instead of Telnet, WPA2/WPA3 on Wi-Fi, and VPNs.
Encryption at rest
Protects data stored on a disk, so a stolen laptop or backup tape is useless without the key. Examples: BitLocker, FileVault, encrypted databases.
There are two families of encryption. Symmetric encryption uses the same key to lock and unlock; it is fast and does the bulk of the work. Asymmetric (public-key) encryption uses a pair of keys: a public key anyone may have, and a private key kept secret. It is slower, so it is used at the start of a connection to prove identity (with certificates) and agree on a symmetric key. HTTPS, SSH and VPNs all use both.
- 1. Plain HTTP: the eavesdropper reads everything. On an open or shared network, a nearby attacker can capture the login form and its password in plain text. Confidentiality is lost.
- 2. HTTPS: the eavesdropper sees only ciphertext. The attacker can still see that you talk to 203.0.113.10, but not what you send. Any change would break the integrity check.
Firewalls: controlling what crosses a boundary
A firewall inspects traffic crossing a boundary, most commonly between a private network and the internet, and allows or blocks it based on a set of rules. The device itself is introduced in Firewalls, and its rules in Firewall basics. Firewalls have grown more advanced over time:
- Packet-filtering firewalls: the earliest kind. They check each packet on its own, against rules based on source and destination address, port, and protocol.
- Stateful firewalls: track the state of active connections. A rule can allow a reply to traffic you started without you having to permit that reverse direction separately. This is standard in almost every modern firewall.
- Next-generation firewalls (NGFW): add deeper inspection. They identify the actual application generating traffic regardless of port, inspect encrypted traffic where policy allows, and build in intrusion prevention.
Access control lists (ACLs)
An ACL is an ordered list of rules, each one permitting or denying traffic that matches specific criteria, applied directly on a router or switch interface. ACLs are checked in order and stop at the first match, so rule order matters a lot. A broad "deny all" rule placed too early will silently block traffic that a more specific rule further down was meant to allow. Like firewalls, ACLs end with an invisible "deny everything else".
💡 In simple terms: an ACL is like a bouncer with a clipboard, checking a list top to bottom and acting on the first rule that matches, not the most specific one, whichever comes first.
Most simple ACLs are stateless: they don't remember conversations, so return traffic needs its own rule. That is one reason a dedicated stateful firewall is used at the internet edge, while ACLs are handy for quick filters inside the network, for example stopping the guest subnet from reaching the management subnet.
Going further (CCNA): writing standard and extended ACLs in Cisco IOS is CCNA material, outside this beginner course. Here, it is enough to understand what an ACL does and why rule order matters.
Defence in depth
No single control stops every threat. That's why real networks layer multiple defences instead of relying on just one. A typical setup combines several of these at once:
If one layer fails or is bypassed, the others are still there. This is also why segmentation (often built with VLANs) matters for security, not just performance. Segmenting a network limits how far an attacker who compromises one device can actually reach. And because some attacks will succeed anyway, the last layers are detection (logs, intrusion detection) and recovery (tested backups).
Common threats these defences exist to stop
- Unauthorized access: someone reaching a system they shouldn't. This often happens through a weak or reused password, or a service left exposed to the internet by accident.
- Denial of service (DoS): overwhelming a system with traffic or requests until it can no longer serve real users. A distributed version (DDoS) does this from many sources at once, which makes it harder to block by filtering just one source address.
- Malware: malicious software that reaches a device, often through a download, email attachment, or compromised website. Once it's there, it acts against the interests of the device's owner. Ransomware, which encrypts files and demands payment, is the most damaging kind today.
- Phishing: tricking a person, rather than a system, into giving up credentials or taking a harmful action. It's a reminder that network defences alone can't stop every attack, since some target people directly.
A few more you will hear about, and what each one attacks:
| Threat | What happens | Harms | Main defences |
|---|---|---|---|
| Eavesdropping (sniffing) | Capturing traffic on a shared network to read it | Confidentiality | Encryption (HTTPS, SSH, WPA3, VPN) |
| Man-in-the-middle | The attacker secretly sits between two parties, reading or changing traffic, e.g. by ARP spoofing or a fake Wi-Fi hotspot | Confidentiality, integrity | Encryption with certificate checks, switch security features |
| Spoofing | Faking a source IP or MAC address, or an email sender, to pretend to be someone else | Integrity | Authentication, filtering, SPF/DMARC for email |
| Password attacks | Guessing, trying leaked passwords ("credential stuffing") | Confidentiality | MFA, long unique passwords, lockouts |
| Ransomware | Malware encrypts files across every share it can reach | Availability | Segmentation, least privilege, offline backups |
| DDoS | A flood of traffic from many sources | Availability | Provider filtering, scrubbing services, spare capacity |
| Misconfiguration | A port opened "temporarily", a default password left on a camera | All three | Change control, regular reviews, scanning |
| Insider threat | A staff member misuses access, on purpose or by mistake | All three | Least privilege, accounting logs |
Real-world scenario: segmenting an office network
An office puts guest Wi-Fi on its own VLAN, with a firewall rule that allows outbound internet access but explicitly denies any traffic toward the internal VLANs where file servers and printers live. If a guest's laptop gets compromised with malware, it still can't reach anything on the internal network. The segmentation contained the damage, even though the firewall rule alone didn't stop the original infection.
Now add the other ideas from this lesson. Staff sign in to the Wi-Fi through a RADIUS server with MFA (authentication), land in the Staff segment because of their group (authorization), and every session is logged (accounting). The file server is reached over encrypted SMB, backups are kept offline, and IT uses separate admin accounts (least privilege). Each layer covers gaps in the others.
When security fails: spotting problems
Security failures rarely announce themselves. Typical signs:
- Firewall logs showing many denied connections from one inside device (it may be infected and scanning).
- Logins at strange hours or from unexpected countries in the accounting logs.
- A server listening on ports nobody can explain.
- Certificate warnings in the browser on a site that normally works (possible man-in-the-middle, or just an expired certificate).
- Sudden slowness or outage of a public service (possible DoS).
Useful commands
See which services a computer offers to the network. Every listening port is a possible way in:
$ sudo ss -tlnp State Recv-Q Send-Q Local Address:Port Peer Address:Port Process LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:(("sshd",pid=812,fd=3)) LISTEN 0 511 0.0.0.0:443 0.0.0.0:* users:(("nginx",pid=1044,fd=6)) LISTEN 0 80 127.0.0.1:3306 0.0.0.0:* users:(("mysqld",pid=930,fd=21)) LISTEN 0 64 0.0.0.0:23 0.0.0.0:* users:(("inetd",pid=701,fd=5))
SSH (22) and HTTPS (443) are expected. The database (3306) listens only on 127.0.0.1, so it can't be reached from the network: good. But port 23 is Telnet, which sends passwords in plain text. It should be turned off.
C:\> netstat -ano -p tcp | findstr LISTENING TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1012 TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4 TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1180 TCP 0.0.0.0:5040 0.0.0.0:0 LISTENING 6120
Port 3389 means Remote Desktop is on. That is fine inside the office behind a firewall, but it should never be reachable from the internet. The last column is the process ID, which you can look up in Task Manager. See Viewing connections on your computer.
From outside, the Port Checker shows what your public address exposes, and the SSL Checker confirms a website's certificate is valid and not about to expire.
Common mistakes
- Relying on one control. Having a firewall is not, on its own, a security plan.
- Thinking NAT is a firewall. It hides addresses as a side effect; it doesn't inspect anything.
- Password-only logins for email, VPN and admin pages. Turn on MFA.
- Everyone is an admin. Daily work with admin rights turns every phishing click into a disaster.
- Leaving defaults: default passwords on cameras and routers, Telnet enabled, unused ports open.
- Not patching. Many attacks use flaws that were fixed months earlier.
- No logs, or logs nobody reads. Accounting only helps if someone looks.
- Security protects confidentiality, integrity and availability (the CIA triad).
- AAA: authentication proves who you are, authorization decides what you may do, accounting records what you did.
- MFA combines different kinds of proof, so a stolen password is not enough.
- Least privilege gives every user, device and program only the access it needs.
- Encryption protects data in transit (HTTPS, SSH, VPN, WPA3) and at rest (disk encryption).
- Firewalls and ACLs filter traffic with ordered rules ending in an implicit deny.
- Defence in depth layers controls, so one failure is not a disaster.
Knowledge check
A DDoS attack floods an online shop so customers can't load the site. Which part of the CIA triad is harmed?
Ana signs in with her password and a phone prompt. The system then lets her open the finance share but not the HR share. Which step decided about the shares?
Which of these is true multi-factor authentication?
An attacker on café Wi-Fi captures all your traffic to a website using HTTPS. What can they read?
A receptionist's PC can reach every server in the company, although she only uses the booking system. Which principle is broken?
Where to go next
Put these ideas to work in the rest of this unit: Firewall basics (rules, implicit deny, stateful inspection), VPN basics (encrypted tunnels) and Network segmentation (zones and allowed flows). For Wi-Fi-specific protection, see Wireless security.