From: Jens Hoffmann on

> (1) What will be size of the firewall policy for an enterprise
> network.

Depends on the needs of the specific enterprise.
Can be between 1 or 2 rules to hundreds of rules and a couple of firewalls
with different rules each.

> (2) What rules in general contain in the rule set i.e., accept. or
> deny

A sensible decision would be to deny any communication which is not
explicitly allowed and wanted.

> (3) What are rules which are at the top of the rule set and which one
> are the end of the rule set,

You are implying a precedence in ordering the rules, which might not
be present in all firewalls.

> (4) and why the rules at the bottom of the ruleset have the lowest
> priority than the rules at the top of the ruleset.

Many firewalls only process the rules top to bottom until they
find a match and then stop processing.

Again, this might not be true for all firewalls.

I personally like: ISBN-13: 978-0201634662 as an introductional book.

Cheers,
Jens