Home▸Cybersecurity▸Stateful Firewall 2D: Connection Tracking & Spoofed-ACK Defense

Stateful Firewall 2D: Connection Tracking & Spoofed-ACK Defense

A 2D top-down view of a real TCP state machine (SYN_SENT to ESTABLISHED to TIME_WAIT) tracked in a stateful firewall's connection table. Fire a spoofed bare-ACK packet and see why a naive stateless filter waves it through while stateful inspection drops it outright. Drag to pan, scroll to zoom.

Cybersecurity2DModerate60 FPS📱 Mobile-adapted⇄ 3D version
2d-network-security-cybersecurity ↗ Open standalone

The 2D companion to the 3D stateful-firewall simulation, showing the exact same mechanism from directly above: a live connection-tracking table walking real TCP sessions through their state machine — SYN_SENT, ESTABLISHED, FIN_WAIT, TIME_WAIT — with packets crossing a firewall line between an internal network and the open internet. Start a new outbound connection and watch the full handshake, data exchange and teardown get tracked entry-by-entry. Then fire a spoofed bare-ACK packet with no real session behind it and flip between stateful and stateless mode: a stateful firewall checks the packet against its real connection table and drops it instantly, while a naive stateless filter — which only checks whether the ACK flag is set — waves it straight through, the exact weakness Nmap's ACK scan exploits to map firewall rulesets from the outside. Drag to pan the view and scroll to zoom in on any lane.

⚙ Under the hood

A top-down 2D view of a real TCP connection getting tracked through SYN_SENT, ESTABLISHED and TIME_WAIT in a live firewall connection table. Fire a spoofed bare-ACK packet and see a stateful firewall reject it while a naive stateless filter lets it through. Drag to pan, scroll to zoom.

cybersecurityfirewalltcpnetwork-securitystateful-inspection

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)