TL;DR: Firewall labs need addresses you control and a network that is not the public internet. A generator can supply the dotted quads for those rules so you are not always testing 10.0.0.1. It cannot supply permission to aim the same rule at the real world. Build the lab, generate a few sources, watch the logs, and tear the rules down. Start the specimens with a random IP draw, then type them into the lab firewall, not into the office edge.
The classroom switch that was not a classroom
An evening course on packet filters met in a room where the “lab” PCs were also on the college network. The instructor generated three addresses, wrote a deny rule for them on a PC that still had a default route, and asked students to test. One of the three addresses answered on port 443. It was a small company’s website that happened to match the draw. The deny rule on a student PC did not take the site down, but the following “test” was a burst of connection attempts from the college’s public address, and the company’s admin mailed the college abuse desk before the class ended. The generator was not the failure. The default route was. A lab without a fence is just a PC.
What a fenced test looks like
Use a virtual network, a spare switch with no uplink, or a firewall appliance whose WAN port is unplugged. Give the test hosts addresses you assign, so you know who should speak. Use generated public-looking addresses only as the pretend outside sources in a rule, and only if those packets cannot leave the room. Better: use the documentation ranges so even a mistake is obviously not a customer. The point of the exercise is the rule logic — allow, deny, log, order — not the discovery of live hosts.
- Source in the rule: a generated or documentation address standing in for “the outside.”
- Destination: your lab host, whose address you configured.
- Proof: a log line on the lab firewall, not a screenshot of someone else’s website failing.
- Cleanup: delete the rules before the VM template is copied for next term.
Rule order beats a scary address
Students fixate on the number and ignore order. A deny for a generated address placed under a permit-any will never fire. A deny placed above a permit will fire and teach the lesson. Generate two sources, write two rules, and predict which log line appears before you click. If the prediction fails, the address is not “bad.” The order is. This is the entire reason to practice with disposable numbers: you can be wrong without paging an on-call engineer.
Also practice a rule you expect to miss. Generate an address, forget to include it, and show the allow. New analysts often believe a firewall denies by mood. A lab log is the antidote. The generated address makes the hit or the miss obvious because it is not mixed with your own management traffic.
Logging volume
A single test connection is enough to prove a rule. A loop that opens a thousand connections to a generated address teaches nothing new and, if the fence is imperfect, becomes the abuse mail. Cap the test at a handful of packets. If you are load-testing a box you own, say so in the plan and keep the target inside the fence. Do not “load-test the internet” because a generator made targets cheap.
Notes worth keeping
Write down the address, the rule, the interface, and the log line that proved it. Those four lines are a portfolio piece. A folder of random addresses without the rule that referenced them is a junk drawer. When the semester ends, the notes can stay and the live rules should not. If a later class imports an old VM, they should not inherit a deny list aimed at whoever owns those draws this year.
If a draw matches a range your organization actually uses, regenerate. Training people to block their own identity range is a prank with a ticket attached. Glance at the first octet. You do not need a perfect registry check to notice you just drew the college’s own block because you have seen it all term.
Management addresses stay off the sample list
The address you use to SSH to the lab firewall is not a fun sample. If a generated deny happens to match your own admin station, the next test locks you out of the box you are learning on. Keep a written note of the management host and glance at it before you commit a rule. The college class aimed outward by mistake. You can also aim inward by accident and spend the rest of the evening on a console cable.
Fence first, then generate
The college class had the generator open and the uplink up. Reverse that order. Unplug or isolate, then mint a few addresses, then write a rule you can explain, then read one log line. When the exercise is over, the addresses can die with the VM. The company’s admin should never have been in the lesson at all.