Firewalls, IDS and IPS for Bankers
A firewall is a gate and an IDS is an alarm. Here is what each does, and what neither can stop.
A firewall decides which network traffic is allowed in and out, according to rules. An intrusion detection system (IDS) watches the traffic that got through and raises an alarm when something looks like an attack. One is a gate, the other a burglar alarm, and a bank needs both.
RBI's 2026 cybersecurity directions require banks to build multi-layered boundary defences: properly configured firewalls, proxies, DMZ perimeter networks, and network-based intrusion prevention and detection systems, with real-time filtering of both inbound and outbound traffic.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Firewall Types
- Packet filter
- Checks each packet's source, destination and port against a rule list. Fast but blind to what the traffic actually contains.
- Stateful inspection
- Remembers established connections and allows only replies that belong to a conversation started from inside.
- Proxy (application-level gateway)
- Stands between the user and the internet, making requests on the user's behalf and inspecting the content at the application level.
- Next-generation firewall
- Adds application awareness, user identity and built-in intrusion prevention to stateful inspection.
- Web application firewall (WAF)
- Sits in front of a website or app and filters malicious web requests, such as known injection patterns.
IDS vs IPS
Position
IDS (detection)
Watches a copy of the traffic, off to the side
IPS (prevention)
Sits inline, in the traffic's path
Action
IDS (detection)
Alerts the security team
IPS (prevention)
Blocks or drops the malicious traffic itself
Control type
IDS (detection)
Detective
IPS (prevention)
Preventive
Risk of a wrong call
IDS (detection)
A false alarm wastes analyst time
IPS (prevention)
A false positive can block genuine customer traffic
| IDS (detection) | IPS (prevention) | |
|---|---|---|
| Position | Watches a copy of the traffic, off to the side | Sits inline, in the traffic's path |
| Action | Alerts the security team | Blocks or drops the malicious traffic itself |
| Control type | Detective | Preventive |
| Risk of a wrong call | A false alarm wastes analyst time | A false positive can block genuine customer traffic |
What Firewalls and IDS Don't Stop
- check_circlePhishing and vishing. The customer authorises the payment; no rule is broken at the network edge.
- check_circleInsider misuse through legitimate access.
- check_circleAttacks inside allowed traffic. SQL injection arrives as an ordinary web request on an allowed port; a network firewall lets it through. A WAF or secure code is the answer.
- check_circleMisconfiguration. A firewall rule left open for a vendor and forgotten is a hole. RBI requires periodic review of firewall configurations and patch levels.
Logs Make These Tools Useful
Firewall and IDS logs are evidence. CERT-In's 2022 directions require organisations to keep logs of all ICT systems for a rolling 180 days within India, and to synchronise system clocks with the NTP servers of the National Informatics Centre or National Physical Laboratory, or servers traceable to them, so that events on different systems can be lined up in time. Targeted scanning of critical networks and denial-of-service attacks, both of which an IDS typically spots, are among the incidents that must be reported to CERT-In within 6 hours.
How the IIBF Exam Tests This
- check_circleControl type: a firewall and an IPS are preventive; an IDS is detective. Questions often hinge on this one word.
- check_circlePlacement: public-facing servers belong in the DMZ, not on the internal network.
- check_circleSignature versus anomaly: only anomaly detection can catch an attack nobody has seen before, at the cost of more false alarms.
- check_circleLimits: a scenario about a customer tricked into sharing an OTP is never solved by a firewall.
FAQs
What is the difference between IDS and IPS?expand_more
An IDS detects suspicious traffic and alerts staff; it is a detective control. An IPS sits inline and blocks the traffic itself; it is a preventive control.
What is a DMZ in network security?expand_more
A separate network zone between the internet and the bank's internal network. Public-facing servers sit there, so a compromise of one does not give direct access to internal systems.
Is a firewall a preventive or detective control?expand_more
Preventive. It blocks traffic that breaks its rules. Its logs support detection, but the firewall's own job is to stop traffic.
How long must firewall logs be kept in India?expand_more
CERT-In's 2022 directions require logs of all ICT systems to be kept securely for a rolling 180 days within India and provided to CERT-In when reporting an incident or when directed.
Next steps
- Vulnerabilitiesarrow_forward
- Database Hackingarrow_forward
- RBI Cyber Frameworkarrow_forward
- Fraud Controlsarrow_forward
120 questions, 2 hours, scored instantly.
