◂ Internal NetworkExternal / Internet ▸
drag to pan · scroll to zoom
Handshake (SYN/ACK) Data Teardown (FIN) Spoofed packet Blocked / bounced

Stateful Firewall 2D: Connection Tracking & Spoofed-ACK Defense

The 2D companion to the 3D stateful-firewall simulation, showing the exact same mechanism from directly above: a live connection-tracking table walking real TCP sessions through their state machine — SYN_SENT, ESTABLISHED, FIN_WAIT, TIME_WAIT — with packets crossing a firewall line between an internal network and the open internet. Start a new outbound connection and watch the full handshake, data exchange and teardown get tracked entry-by-entry. Then fire a spoofed bare-ACK packet with no real session behind it and flip between stateful and stateless mode: a stateful firewall checks the packet against its real connection table and drops it instantly, while a naive stateless filter — which only checks whether the ACK flag is set — waves it straight through, the exact weakness Nmap's ACK scan exploits to map firewall rulesets from the outside. Drag to pan the view and scroll to zoom in on any lane.