Routelearn.net
Course menu

Unit 12: Network Security FundamentalsLesson 12.1 (1 of 4 in this unit)66 of 84 in the Network Fundamentals course

Basic network security

The core ideas behind defending a network: what is being protected (confidentiality, integrity, availability), how to decide who gets in (authentication, authorization, accounting), and the encryption, firewalls and layered defences that put those ideas into practice. These principles go beyond any single product.

Beginner · 18 min read · Before this: What is an IP address?, Port numbers and sockets, Firewalls

Network security is the set of policies, controls and technologies that protect the confidentiality, integrity and availability of a network and its data, controlling who may use which resources and recording what they do.

In simple terms: Network security means keeping the wrong people out, keeping data private and unchanged, and keeping the network running. It relies on several layers of defence, such as logins, encryption and firewalls.

Network security isn't about any single product. It's a set of principles for controlling what traffic is allowed to go where, who is allowed to do what, and for catching it when something goes wrong anyway. This lesson covers the foundational concepts that everything else in network security builds on. The next three lessons then put them into practice: Firewall basics, VPN basics and Network segmentation.

💡 In simple terms: think of an office building. Doors with locks keep strangers out. Staff badges prove who you are and open only the rooms you need. Sealed envelopes keep letters private. Cameras record who went where. Network security uses the same ideas, just for data.

What network security is, and why it exists

Network security is everything done to protect a network and the data that travels across it from being read, changed, misused or stopped by people who shouldn't. It is needed because networks were originally built to deliver traffic, not to question it. A router forwards any packet it has a route for; a switch delivers any frame to the right port. Early protocols such as Telnet, FTP and HTTP even sent passwords as plain text. Security was added later, in layers.

Security sits everywhere in the network: on each device (passwords, updates, host firewalls), at the boundaries between networks (firewalls), on the links (encryption), and in the people and processes (training, logging, access reviews).

The CIA triad: what is being protected

Security people describe their goals with three words, known as the CIA triad. (Nothing to do with the intelligence agency.) Every attack harms at least one of them, and every defence protects at least one.

🔒 Confidentiality

Only the right people can read the data. A stranger on café Wi-Fi must not be able to read your email or passwords.

Protected by: Encryption, access control, MFA

✅ Integrity

Data is not changed, by accident or on purpose, without anyone noticing. A bank transfer of €100 must not become €10,000 on the way.

Protected by: Hashes and integrity checks, digital signatures, change logs

🟢 Availability

Systems and data are there when people need them. The online shop must stay up during the sale.

Protected by: Redundant links and devices, backups, DoS protection

The three pull against each other. A system locked in a safe with no network is very confidential but not very available. Good security is about the right balance for each system: a public website needs availability and integrity more than confidentiality; a payroll database needs all three.

AAA: who gets in, what they can do, and what they did

Controlling access to networks and devices follows three steps, known as AAA:

StepQuestion it answersExample
AuthenticationWho are you? Prove it.Ana signs in to the Wi-Fi with her username, password and a phone prompt
AuthorizationWhat are you allowed to do?Ana is in the Finance group, so she may reach the accounts server but not the switch admin pages
AccountingWhat did you do, and when?A log records that Ana connected at 09:02 from 192.168.10.23 and disconnected at 17:31

In a business, these checks usually happen on a central AAA server rather than on each device. Wi-Fi access points, VPN gateways and switches all ask the same server, so a user's account can be disabled in one place. The most common protocol for this is RADIUS (UDP ports 1812 for authentication and 1813 for accounting). For logging in to network devices themselves, TACACS+ (TCP 49) is also common.

Step 1 of 5 · Sign-in
Office network · the AP and AAA server share a secret
Ana's laptop
joining office Wi-Fi
Access point
asks on her behalf
AAA server (RADIUS)
192.168.99.10
The three As in one Wi-Fi sign-in: prove identity, decide access, record the session.

Authentication factors and MFA

There are three kinds of proof, called factors:

Something you know

A password or PIN. Easy to steal through phishing, guessing or reuse on another site.

Something you have

A phone with an authenticator app, a hardware security key, a smart card.

Something you are

A fingerprint or face scan, usually used to unlock the device that holds the key.

Multi-factor authentication (MFA) requires two or more different kinds. A password plus a code from a phone app is MFA; two passwords are not. MFA matters because stolen passwords are the most common way in: with MFA, a phished password alone is not enough. Hardware security keys and passkeys are the strongest options, because they also refuse to work on a fake website.

⚠️ Attackers sometimes send dozens of MFA push prompts hoping the user taps "Approve" to make them stop. Never approve a sign-in you didn't start.

Least privilege

The principle of least privilege says every person, device and program should have only the access it needs to do its job, and no more. It applies at every level:

  • User accounts: staff use normal accounts day to day; admin rights are separate and used only when needed.
  • Network access: a firewall rule allows the reception PC to reach the booking server on one port, not "anything, anywhere".
  • Devices: a printer has no reason to reach the payroll database, so it can't.
  • Time: a contractor's VPN account expires when the contract does.

Least privilege limits damage. If an account or device is compromised, the attacker only gets what that account could do. It is the idea behind the implicit deny in Firewall basics and behind Network segmentation.

Encryption: keeping data private and unchanged

Encryption scrambles data with a secret key so that only someone with the right key can read it. Readable data is called plaintext; scrambled data is ciphertext. Modern encryption also adds an integrity check, so any change to the ciphertext is detected.

Encryption in transit

Protects data while it crosses a network. Examples: HTTPS (TLS) for websites, SSH instead of Telnet, WPA2/WPA3 on Wi-Fi, and VPNs.

Encryption at rest

Protects data stored on a disk, so a stolen laptop or backup tape is useless without the key. Examples: BitLocker, FileVault, encrypted databases.

There are two families of encryption. Symmetric encryption uses the same key to lock and unlock; it is fast and does the bulk of the work. Asymmetric (public-key) encryption uses a pair of keys: a public key anyone may have, and a private key kept secret. It is slower, so it is used at the start of a connection to prove identity (with certificates) and agree on a symmetric key. HTTPS, SSH and VPNs all use both.

Your laptop10.20.4.117attackerEavesdroppersame Wi-FiCafé Wi-FiInternetWebsite203.0.113.10
  1. 1. Plain HTTP: the eavesdropper reads everything. On an open or shared network, a nearby attacker can capture the login form and its password in plain text. Confidentiality is lost.
  2. 2. HTTPS: the eavesdropper sees only ciphertext. The attacker can still see that you talk to 203.0.113.10, but not what you send. Any change would break the integrity check.
Encryption doesn't stop people capturing traffic. It makes what they capture useless.

Firewalls: controlling what crosses a boundary

A firewall inspects traffic crossing a boundary, most commonly between a private network and the internet, and allows or blocks it based on a set of rules. The device itself is introduced in Firewalls, and its rules in Firewall basics. Firewalls have grown more advanced over time:

  • Packet-filtering firewalls: the earliest kind. They check each packet on its own, against rules based on source and destination address, port, and protocol.
  • Stateful firewalls: track the state of active connections. A rule can allow a reply to traffic you started without you having to permit that reverse direction separately. This is standard in almost every modern firewall.
  • Next-generation firewalls (NGFW): add deeper inspection. They identify the actual application generating traffic regardless of port, inspect encrypted traffic where policy allows, and build in intrusion prevention.

Access control lists (ACLs)

An ACL is an ordered list of rules, each one permitting or denying traffic that matches specific criteria, applied directly on a router or switch interface. ACLs are checked in order and stop at the first match, so rule order matters a lot. A broad "deny all" rule placed too early will silently block traffic that a more specific rule further down was meant to allow. Like firewalls, ACLs end with an invisible "deny everything else".

💡 In simple terms: an ACL is like a bouncer with a clipboard, checking a list top to bottom and acting on the first rule that matches, not the most specific one, whichever comes first.

Most simple ACLs are stateless: they don't remember conversations, so return traffic needs its own rule. That is one reason a dedicated stateful firewall is used at the internet edge, while ACLs are handy for quick filters inside the network, for example stopping the guest subnet from reaching the management subnet.

Going further (CCNA): writing standard and extended ACLs in Cisco IOS is CCNA material, outside this beginner course. Here, it is enough to understand what an ACL does and why rule order matters.

Defence in depth

No single control stops every threat. That's why real networks layer multiple defences instead of relying on just one. A typical setup combines several of these at once:

Internet
Untrusted
Firewall
Boundary filtering
Segmentation
Isolates internal zones
Access control
AAA, MFA, least privilege
Hardened host
Updates, host firewall, encryption
Internal server
Protected
Layered defences between the internet and an internal server.

If one layer fails or is bypassed, the others are still there. This is also why segmentation (often built with VLANs) matters for security, not just performance. Segmenting a network limits how far an attacker who compromises one device can actually reach. And because some attacks will succeed anyway, the last layers are detection (logs, intrusion detection) and recovery (tested backups).

Common threats these defences exist to stop

  • Unauthorized access: someone reaching a system they shouldn't. This often happens through a weak or reused password, or a service left exposed to the internet by accident.
  • Denial of service (DoS): overwhelming a system with traffic or requests until it can no longer serve real users. A distributed version (DDoS) does this from many sources at once, which makes it harder to block by filtering just one source address.
  • Malware: malicious software that reaches a device, often through a download, email attachment, or compromised website. Once it's there, it acts against the interests of the device's owner. Ransomware, which encrypts files and demands payment, is the most damaging kind today.
  • Phishing: tricking a person, rather than a system, into giving up credentials or taking a harmful action. It's a reminder that network defences alone can't stop every attack, since some target people directly.

A few more you will hear about, and what each one attacks:

ThreatWhat happensHarmsMain defences
Eavesdropping (sniffing)Capturing traffic on a shared network to read itConfidentialityEncryption (HTTPS, SSH, WPA3, VPN)
Man-in-the-middleThe attacker secretly sits between two parties, reading or changing traffic, e.g. by ARP spoofing or a fake Wi-Fi hotspotConfidentiality, integrityEncryption with certificate checks, switch security features
SpoofingFaking a source IP or MAC address, or an email sender, to pretend to be someone elseIntegrityAuthentication, filtering, SPF/DMARC for email
Password attacksGuessing, trying leaked passwords ("credential stuffing")ConfidentialityMFA, long unique passwords, lockouts
RansomwareMalware encrypts files across every share it can reachAvailabilitySegmentation, least privilege, offline backups
DDoSA flood of traffic from many sourcesAvailabilityProvider filtering, scrubbing services, spare capacity
MisconfigurationA port opened "temporarily", a default password left on a cameraAll threeChange control, regular reviews, scanning
Insider threatA staff member misuses access, on purpose or by mistakeAll threeLeast privilege, accounting logs

Real-world scenario: segmenting an office network

An office puts guest Wi-Fi on its own VLAN, with a firewall rule that allows outbound internet access but explicitly denies any traffic toward the internal VLANs where file servers and printers live. If a guest's laptop gets compromised with malware, it still can't reach anything on the internal network. The segmentation contained the damage, even though the firewall rule alone didn't stop the original infection.

Now add the other ideas from this lesson. Staff sign in to the Wi-Fi through a RADIUS server with MFA (authentication), land in the Staff segment because of their group (authorization), and every session is logged (accounting). The file server is reached over encrypted SMB, backups are kept offline, and IT uses separate admin accounts (least privilege). Each layer covers gaps in the others.

When security fails: spotting problems

Security failures rarely announce themselves. Typical signs:

  • Firewall logs showing many denied connections from one inside device (it may be infected and scanning).
  • Logins at strange hours or from unexpected countries in the accounting logs.
  • A server listening on ports nobody can explain.
  • Certificate warnings in the browser on a site that normally works (possible man-in-the-middle, or just an expired certificate).
  • Sudden slowness or outage of a public service (possible DoS).

Useful commands

See which services a computer offers to the network. Every listening port is a possible way in:

Example output from a Linux server, written for this lesson
$ sudo ss -tlnp
State   Recv-Q  Send-Q   Local Address:Port    Peer Address:Port  Process
LISTEN  0       128            0.0.0.0:22           0.0.0.0:*      users:(("sshd",pid=812,fd=3))
LISTEN  0       511            0.0.0.0:443          0.0.0.0:*      users:(("nginx",pid=1044,fd=6))
LISTEN  0       80           127.0.0.1:3306         0.0.0.0:*      users:(("mysqld",pid=930,fd=21))
LISTEN  0       64             0.0.0.0:23           0.0.0.0:*      users:(("inetd",pid=701,fd=5))

SSH (22) and HTTPS (443) are expected. The database (3306) listens only on 127.0.0.1, so it can't be reached from the network: good. But port 23 is Telnet, which sends passwords in plain text. It should be turned off.

Example output from a Windows PC, written for this lesson
C:\> netstat -ano -p tcp | findstr LISTENING
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       1012
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:3389           0.0.0.0:0              LISTENING       1180
  TCP    0.0.0.0:5040           0.0.0.0:0              LISTENING       6120

Port 3389 means Remote Desktop is on. That is fine inside the office behind a firewall, but it should never be reachable from the internet. The last column is the process ID, which you can look up in Task Manager. See Viewing connections on your computer.

From outside, the Port Checker shows what your public address exposes, and the SSL Checker confirms a website's certificate is valid and not about to expire.

Common mistakes

  • Relying on one control. Having a firewall is not, on its own, a security plan.
  • Thinking NAT is a firewall. It hides addresses as a side effect; it doesn't inspect anything.
  • Password-only logins for email, VPN and admin pages. Turn on MFA.
  • Everyone is an admin. Daily work with admin rights turns every phishing click into a disaster.
  • Leaving defaults: default passwords on cameras and routers, Telnet enabled, unused ports open.
  • Not patching. Many attacks use flaws that were fixed months earlier.
  • No logs, or logs nobody reads. Accounting only helps if someone looks.
✅ Key takeaways
  • Security protects confidentiality, integrity and availability (the CIA triad).
  • AAA: authentication proves who you are, authorization decides what you may do, accounting records what you did.
  • MFA combines different kinds of proof, so a stolen password is not enough.
  • Least privilege gives every user, device and program only the access it needs.
  • Encryption protects data in transit (HTTPS, SSH, VPN, WPA3) and at rest (disk encryption).
  • Firewalls and ACLs filter traffic with ordered rules ending in an implicit deny.
  • Defence in depth layers controls, so one failure is not a disaster.

Knowledge check

Predict · scenario 1

A DDoS attack floods an online shop so customers can't load the site. Which part of the CIA triad is harmed?

Predict · scenario 2

Ana signs in with her password and a phone prompt. The system then lets her open the finance share but not the HR share. Which step decided about the shares?

Predict · scenario 3

Which of these is true multi-factor authentication?

Predict · scenario 4

An attacker on café Wi-Fi captures all your traffic to a website using HTTPS. What can they read?

Predict · scenario 5

A receptionist's PC can reach every server in the company, although she only uses the booking system. Which principle is broken?

Where to go next

Put these ideas to work in the rest of this unit: Firewall basics (rules, implicit deny, stateful inspection), VPN basics (encrypted tunnels) and Network segmentation (zones and allowed flows). For Wi-Fi-specific protection, see Wireless security.

FAQ

Is NAT enough to keep my network secure?
No. NAT has a side effect that looks like security: devices behind it aren't directly addressable from the internet by default. But it was never designed as a security control. It gives you no protection against threats that arrive through traffic you started yourself, like a malicious download. See How NAT and PAT work for what it actually does.
What's the difference between a firewall and an access control list?
An ACL is a specific mechanism: an ordered list of rules matched against traffic, often configured directly on a router or switch. A firewall is a broader category of device or feature. It may use ACL-style rules internally, but typically adds more, like connection state tracking, deep packet inspection, and logging, than a plain ACL provides on its own.
What is the difference between authentication and authorization?
Authentication answers 'who are you?' (proving your identity, for example with a password and a phone prompt). Authorization answers 'what are you allowed to do?' (which systems and actions your identity is permitted). You are always authenticated first, then authorized.
Do small home networks actually need to think about any of this?
The basics still matter: keep router firmware updated, use a strong Wi-Fi password, turn on MFA for important accounts, and don't expose services to the internet you don't intend to. The more advanced material (dedicated firewalls, segmentation, IDS/IPS) becomes relevant once a network has multiple trust levels to keep apart, like an office separating guest Wi-Fi from internal servers.