Stateless vs Stateful ACL

Stateless vs Stateful ACL

Stateless vs Stateful ACL
Stateless vs Stateful ACL
3 weeks ago - last edited 19 hours ago

Background:

 

This article aims to provide an explanation and comparison between the Stateless and Stateful ACL.

 

This Article Applies to:

 

Omada routers with Stateful ACL upgrades.

 

Term Explanation:

 

Stateless ACL:

 

Stateless ACL operates based on static rules to handle traffic. It decides whether to allow traffic based solely on predefined conditions (such as IP address, port number, etc.), without considering the context or previous traffic.
Each packet is checked independently of others. The ACL checks the packet's source and destination IP, port numbers, and other factors to decide whether to allow or deny access. This method does not track the state of the connection, so each traffic check is isolated.


Advantages:

Simpler to implement, and generally faster as it doesn’t require maintaining state information.

 

Disadvantages:

It cannot handle connection states, so for protocols like TCP (which rely on connection state), it may not be as effective or secure. Attackers can exploit this lack of context to bypass the ACL.

 

Stateful ACL:

 

Stateful ACL not only checks the packet’s basic information (such as IP, ports), but also tracks the state of the connection. It maintains a context of the traffic and ensures that packets are part of a valid session.
Stateful ACL keeps a state table, tracking the connection's status (e.g., whether a TCP handshake has occurred). It ensures that packets belong to an established connection (e.g., ensuring that only packets from an active session are allowed). For example, for a TCP connection, it can check the SYN, ACK flags and permit only valid communication.


Advantages:

More secure, particularly for dynamic protocols such as TCP. It can prevent attacks like SYN floods and other types of session hijacking.


Disadvantages:

Potentially lower performance, as it requires maintaining and updating a connection state table and checking each packet more thoroughly.

 

Key Differences:

 

How it works:

Stateless ACL: Does not track connection state; each packet is treated independently.
Stateful ACL: Tracks the connection state and only allows packets from active, valid connections.

 

Use case:

Stateless ACL: Suitable for simple access control where state tracking is not necessary (e.g., basic filtering).
Stateful ACL: Suitable for more complex scenarios where connection tracking is required (e.g., securing TCP connections or handling dynamic protocols).

 

In Omada router, the stateful ACL can be in the States. It determines the type of stateful ACL rule.

Here is the explanation from the User Guide:
It is recommended to use the default Auto type.
New - Match the connections of the initial state. For example, a SYN packet arrives in a TCP connection, or the router only receives traffic in one direction.
Established - Match the connections that have been established. In other words, the firewall has seen the bidirectional communication of this connection.
Related - Match the associated sub-connections of a main connection, such as a connection to a FTP data channel.
Invalid - Match the connections that do not behave as expected.

 

Update Logs:

 

Nov 11th, 2024:

Release of the article.

 

Recommended Threads:

 

How to Block Unwanted WAN IP Address from Your Server

How to Configure ACL to Block Unauthorized VPN Clients Bypassing the Portal

ACL Guide Compilation

 

Feedback:

 

  • If this was helpful, welcome to give us Kudos by clicking the upward triangle below.
  • If there is anything unclear in this solution post, please feel free to comment below.

 

Thank you for your support and contribution to TP-Link Community!

 

------------------------------------------------------------------------------------------------

Have other off-topic issues to report? 

Welcome to > Start a New Thread < and elaborate on the issue for assistance.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  2      
  2      
#1
Options
4 Reply
Re:Stateless vs Stateful ACL
Monday

  @Clive_A Wann wird die Zustandsbehaftete ACL für IP Guppen bei dem Router ER605 möglich sein?

  0  
  0  
#2
Options
Re:Stateless vs Stateful ACL
Tuesday

Hi @Mathias86 

Thanks for posting in our business forum.

Mathias86 wrote

  @Clive_A Wann wird die Zustandsbehaftete ACL für IP Guppen bei dem Router ER605 möglich sein?

Ja. ER605 V2 has supported Stateful ACL.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#3
Options
Re:Stateless vs Stateful ACL
Yesterday - last edited Yesterday

  @Clive_A Aber nur für Netz to Netz und nicht IP-Guppe zur IP-Gruppe!

Wann wird IP Group zu IP Group möglich sein?

 

Hardware:

ER605 v2.0  2.2.6

Windows Controller  5.14.32.3

 

Siehe auch:

https://community.tp-link.com/en/business/forum/topic/606980?sortDir=ASC&page=2

  0  
  0  
#4
Options
Re:Stateless vs Stateful ACL
Yesterday

Hi @Mathias86 
Thanks for posting in our business forum.

Mathias86 wrote

  @Clive_A Aber nur für Netz to Netz und nicht IP-Guppe zur IP-Gruppe!

Wann wird IP Group zu IP Group möglich sein?

 

 

Hardware:

ER605 v2.0  2.2.6

Windows Controller  5.14.32.3

 

Siehe auch:

https://community.tp-link.com/en/business/forum/topic/606980?sortDir=ASC&page=2

As described in the link, this feature is placed behind other top features. The V5.15.X is fulfilling the features requested. It might take a year. We have no information about the V5.16 yet.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#5
Options