← All cheat sheets

FIREWALK

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Firewalk is an active reconnaissance tool that determines which
protocols a firewall or gateway will pass. It sends TCP/UDP packets
with TTL values designed to expire one hop past the firewall,
revealing open ports in the ACL.

BASIC USAGE#

firewalk -S<port_start>-<port_end> <gateway_ip> <target_ip>
                                 # Scan port range through gateway
firewalk -pTCP <gateway_ip> <target_ip>
                                 # Use TCP protocol (default)
firewalk -pUDP <gateway_ip> <target_ip>
                                 # Use UDP protocol

SCAN OPTIONS#

firewalk -S1-1024 <gw> <tgt>    # Scan ports 1-1024
firewalk -S80,443,8080 <gw> <tgt>
                                 # Scan specific ports
firewalk -S1-65535 <gw> <tgt>   # Full port range scan
firewalk -n <gw> <tgt>          # Do not resolve hostnames

PROTOCOL OPTIONS#

firewalk -pTCP <gw> <tgt>       # TCP scan (default)
firewalk -pUDP <gw> <tgt>       # UDP scan

TIMING & NETWORK#

firewalk -t <timeout> <gw> <tgt>
                                 # Set packet timeout (ms)
firewalk -d <port> <gw> <tgt>   # Set initial destination port
firewalk -r <gw> <tgt>          # Strict RFC adherence
firewalk -T 1-2 <gw> <tgt>     # Set initial/ramped TTL

NETWORK INTERFACE#

firewalk -i eth0 <gw> <tgt>     # Specify network interface
firewalk -s <port> <gw> <tgt>   # Set source port

EXAMPLES#

# Scan common web ports through firewall
firewalk -S80,443,8080,8443 192.168.1.1 10.0.0.1

# Full TCP port scan
firewalk -pTCP -S1-1024 192.168.1.1 10.0.0.1

# UDP scan for DNS, SNMP, TFTP
firewalk -pUDP -S53,161,69 192.168.1.1 10.0.0.1

# Scan with specific interface
firewalk -i eth0 -S1-100 192.168.1.1 10.0.0.1

HOW IT WORKS#

# Phase 1: Ramping
# - Determines hop count to the gateway (like traceroute)
# - Sends packets with incrementing TTL values
# - Identifies the exact TTL needed to reach the gateway

# Phase 2: Scanning
# - Sends packets with TTL = gateway_hops + 1
# - If firewall allows the traffic: ICMP TTL exceeded from next hop
# - If firewall blocks the traffic: no response (filtered)

INTERPRETING RESULTS#

# "A" = ACL allows the port (open/forwarded)
# "F" = Filtered (firewall blocks the port)
# "T" = Timed out (no response, likely filtered)

NOTES#

- Requires root privileges
- Gateway IP = firewall/router you want to test
- Target IP = host beyond the firewall
- Works best when there is exactly one hop past the gateway
- May trigger IDS/IPS alerts
- Some firewalls detect and block firewalk scans
- Stateful firewalls may give inaccurate results