Routelearn.net
Course menu

Unit 2: Network DevicesLesson 2.6 (6 of 8 in this unit)10 of 84 in the Network Fundamentals course

Firewalls

A firewall is the network's security guard. It sits where traffic passes between two networks and lets through only what is allowed. This lesson introduces the firewall as a device: what it is, where it goes, and the different kinds you will meet.

Beginner · 12 min read · Before this: Routers, Switches

A firewall is a network security device or software that sits between networks or zones of different trust and permits or blocks traffic according to a configured security policy.

In simple terms: A firewall is like a guard at a gate between networks. It checks the traffic trying to pass and lets through only what the rules allow.

A firewall is a device (or software) that checks network traffic and decides whether to allow it or block it, following a list of rules written by an administrator. The name comes from buildings: a firewall is a wall that stops a fire spreading from one part of a building to another.

💡 In simple terms: a firewall is the security desk at the entrance of an office building. Staff walk out freely and come back in. Visitors are only let in if they are expected and are going to an allowed place. Everyone else is turned away, and the desk writes it all down in a logbook.

Why firewalls exist

A router's job is to deliver packets. If it knows a route, it forwards the packet. It doesn't ask whether the packet should be delivered. That is a problem when one side of the router is the internet: millions of machines scan the internet all day looking for open doors. A firewall adds the missing question: is this traffic allowed?

  • Keep unwanted traffic from the internet out of the private network.
  • Control what inside users and devices can reach outside.
  • Separate parts of a network that need different levels of trust, such as guests, staff and servers.
  • Record what was allowed and blocked, for troubleshooting and security investigations.

Where a firewall sits

At the edge

The most common place is the network edge: the point where the private network meets the internet. All traffic in and out must pass through it, so it is the natural checkpoint.

outsideinsideInternetScanner198.51.100.66Firewalloutside 203.0.113.2SwitchStaff PC192.168.10.11File server192.168.10.20
  1. 1. A staff PC opens a website. Inside-to-outside web traffic is allowed by the rules, so the firewall passes it and remembers the conversation.
  2. 2. The reply is let back in. It belongs to a conversation the PC started, so the firewall lets it through.
  3. 3. A scanner tries the file server. Nobody inside asked for this, and no rule allows it. The firewall drops it and logs it.
Traffic that starts inside is allowed out and its replies come back; unsolicited traffic from outside is dropped.

Between zones

Firewalls group interfaces into zones, each with a trust level. Rules then say what may pass from one zone to another. A common design has three zones:

Outside (untrusted)

The internet. Nothing from here is trusted by default.

DMZ (semi-trusted)

Servers the public must reach, such as a web server. If one is broken into, the attacker is still not inside the main network.

Inside (trusted)

Staff PCs, internal servers, printers. The most protected zone.

DMZCustomer198.51.100.25InternetFirewallWeb serverDMZ 172.16.1.10Staff PCinside 192.168.10.11Databaseinside 192.168.10.50
  1. 1. A customer opens the website. Outside → DMZ on TCP 443 is allowed, so it reaches the web server.
  2. 2. The web server queries the database. A specific rule allows the web server, and only the web server, to reach the database's port.
  3. 3. The customer tries the database directly. Outside → inside is not allowed. Blocked.
  4. 4. Staff manage the web server. Inside → DMZ is allowed, so staff can update the site.

Larger networks also put firewalls inside the network, for example between the guest Wi-Fi and the office, or in front of the finance servers. Splitting a network this way is covered in Network segmentation.

Network firewalls and host firewalls

Network firewallHost firewall
What it isA dedicated device (or virtual appliance) on the network pathSoftware on one computer, e.g. Windows Defender Firewall, ufw on Linux
ProtectsEverything behind itOnly the device it runs on
SeesOnly traffic that crosses itAll traffic to and from that device, including from the same LAN
Managed byNetwork or security teamThe device owner, or IT through central policies
ExampleOffice edge firewallA laptop on café Wi-Fi blocking file sharing

Use both. They protect against different things. This idea of several layers of protection is called defence in depth; see Basic network security.

Firewalls also come in other forms: a feature inside a home router, a virtual firewall running on a server, and cloud firewalls (security groups) that protect cloud servers, covered in Cloud networking basics.

Important parts of a firewall

PartWhat it does
Interfaces and zonesEach network port connects to a network, and belongs to a zone such as inside, outside or DMZ
Rule table (policy)An ordered list: which source, destination and service is allowed or denied
Connection (state) tableThe firewall's memory of conversations in progress, so replies can come back
LogsA record of allowed and blocked connections
ManagementA web page, command line or central manager for rules and monitoring

How a firewall decides, in brief

Packet arrives
on the outside interface
Part of a known conversation?
if yes, allow it straight away
Check the rules top to bottom
first match wins
Allow or ❌ deny
no match = deny
Log it
if logging is on
A simplified view. The details of rules and connection tracking come later in the course.

Two ideas matter here. First, a rule list usually ends with an invisible deny everything else: if no rule allows something, it is blocked. Second, modern firewalls are stateful: they remember each conversation started from inside and automatically let its replies back in, without a separate rule. Writing rules and how stateful inspection works are taught in Firewall basics.

What a firewall looks at in a packet

A traditional firewall reads the IP header and the TCP or UDP header. That gives it five facts, often called the 5-tuple:

FieldExampleComes from
Source IP198.51.100.25IP header (Layer 3)
Destination IP203.0.113.10IP header (Layer 3)
ProtocolTCPIP header (Layer 3)
Source port51514TCP header (Layer 4)
Destination port443 (HTTPS)TCP header (Layer 4)

The destination port tells the firewall which service is wanted: 443 for HTTPS, 22 for SSH, 3389 for Remote Desktop. See Common ports to know. Edge firewalls very often do NAT too, so the addresses can change as the packet passes through.

Next-generation firewalls

Port numbers are a weak clue. Almost everything now runs over port 443, and any program can use any port. A next-generation firewall (NGFW) looks deeper, into the application data itself (Layer 7). It adds features such as:

  • Application awareness: it recognises the actual app (a video service, a file-sharing tool) whatever port it uses, and can allow one and block another.
  • User identity: rules by person or group ("Finance may use the banking app") instead of only by IP address.
  • Intrusion prevention (IPS): it spots known attack patterns in traffic and blocks them.
  • URL filtering and malware scanning: it blocks known bad websites and checks downloads.
  • TLS inspection: with the organisation's own certificate installed on devices, it can decrypt and inspect encrypted traffic. This is powerful but raises privacy questions.
OSI layerRouterIP addressesFirewallIPs + portsNGFW+ applications
L7 Application––✓
L6 Presentation––some
L5 Session––some
L4 Transport–✓✓
L3 Network✓✓✓
L2 Data Link✓✓✓
L1 Physical✓✓✓
A traditional firewall decides using Layers 3 and 4. A next-generation firewall also understands Layer 7 (applications).

A real-world example: the home router

Your home router contains a simple firewall. When your laptop (192.168.1.20) opens a website, the router records the conversation and lets the replies back in. When a stranger on the internet sends a connection attempt to your public address 203.0.113.45, the router has no matching conversation and no rule allowing it, so it drops it. That is why your printer and smart TV are not reachable from the internet, unless you open a door yourself with port forwarding.

InternetStranger198.51.100.66Home routerWAN 203.0.113.45Laptop192.168.1.20Printer192.168.1.40
  1. 1. The laptop opens a website. Outbound traffic is allowed. The router notes the conversation in its state table.
  2. 2. The reply matches the conversation. It comes back to 203.0.113.45 and is passed to the laptop.
  3. 3. A stranger tries to reach the printer. No conversation and no port-forward rule match, so the home router drops it.
Even a basic home router blocks unsolicited inbound connections by default.

⚠️ Every port-forwarding rule you add is a hole in that firewall. Only forward what you really need, and remove rules you no longer use.

When a firewall causes problems

SymptomLikely causeWhat to check
Ping works but an application doesn't connectThe firewall allows ICMP but blocks the app's portTest the exact port; check the firewall logs
Connection hangs, then times outTraffic is silently droppedLogs on the network firewall and the host firewall
Connection refused instantlyUsually no program listening, or a firewall sending a rejectIs the service running? Is a reject rule in place?
Works from inside, not from the internetNo inbound rule or port forwardEdge firewall rules and NAT
Everything stops when the firewall failsThe firewall is a single point of failure on the pathHardware status; businesses use a pair of firewalls for this reason

A firewall that crashes usually fails closed: it blocks everything rather than letting everything through. That is safer, but it means a firewall outage is a network outage.

Useful commands

Check whether the host firewall is on:

Example output from a Windows PC, written for this lesson
C:\>netsh advfirewall show allprofiles state
Domain Profile Settings:
----------------------------------------------------------------------
State                                 ON

Private Profile Settings:
----------------------------------------------------------------------
State                                 ON

Public Profile Settings:
----------------------------------------------------------------------
State                                 ON
Ok.
Example output from an Ubuntu Linux server, written for this lesson
$ sudo ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), disabled (routed)
New profiles: skip

To                         Action      From
--                         ------      ----
22/tcp                     ALLOW IN    192.168.10.0/24
443/tcp                    ALLOW IN    Anywhere

Incoming traffic is denied by default. SSH is allowed only from the office LAN, and HTTPS from anywhere.

Test whether a particular port gets through, end to end:

Example output from a Windows PC, written for this lesson
PS C:\>Test-NetConnection 192.168.10.20 -Port 445
WARNING: TCP connect to (192.168.10.20 : 445) failed

ComputerName           : 192.168.10.20
RemoteAddress          : 192.168.10.20
RemotePort             : 445
InterfaceAlias         : Ethernet
SourceAddress          : 192.168.10.11
PingSucceeded          : True
TcpTestSucceeded       : False

Ping succeeds but TCP 445 fails: the server is reachable, so something (very often a firewall) is blocking that port. To test a public address from outside, try the Port Checker.

Common mistakes

  • Thinking “ping works” means the firewall allows everything. Firewalls filter per protocol and port.
  • Forgetting the host firewall. The network firewall allows the traffic, but Windows Firewall on the server blocks it.
  • Turning the firewall off “just to test” and forgetting to turn it back on.
  • Opening a port to “Anywhere” when only a few addresses need it.
  • Believing a firewall makes a network safe on its own. It is one layer of protection among several.
✅ Key takeaways
  • A firewall allows or blocks traffic based on rules; anything not allowed is denied.
  • It usually sits at the edge between the LAN and the internet, and can also separate internal zones such as a DMZ.
  • Network firewalls protect everything behind them; host firewalls protect one device everywhere it goes.
  • Traditional firewalls decide on IPs, protocol and ports (Layers 3–4); NGFWs also understand applications (Layer 7).
  • Stateful firewalls let replies to inside-initiated traffic back in automatically.

Knowledge check

Predict · scenario 1

A company wants customers on the internet to reach its web server, but never its internal database. Where should the web server go?

Predict · scenario 2

Your laptop is on café Wi-Fi. Which firewall protects it from other people on that Wi-Fi?

Predict · scenario 3

A rule allows TCP 443 to the web server. A packet arrives for TCP 3389 (Remote Desktop) on the same server, and no other rule matches.

Predict · scenario 4

Staff use a chat app over HTTPS (port 443). Management wants to block that app but keep normal websites working. What is needed?

Where to go next

You'll write firewall rules and see stateful inspection in action in Firewall basics. Next in this unit: Wireless access points.

FAQ

Is my home router a firewall?
Partly. Home routers block unsolicited connections from the internet by default, mostly as a side effect of NAT plus a simple built-in firewall. They have far fewer features than a business firewall, but they do stop the internet from reaching your devices directly.
If I have a network firewall, do I still need the firewall on my laptop?
Yes. The network firewall only sees traffic that crosses it. It can't protect your laptop from another device on the same LAN, or on a café's Wi-Fi. The host firewall protects the device wherever it goes.
Is a firewall the same as antivirus?
No. A firewall decides which network connections are allowed. Antivirus looks for malicious files and programs on a device. Next-generation firewalls add some malware scanning of traffic, but they don't replace protection on the device itself.
Can a router be a firewall?
Many routers can filter traffic with access lists, and many firewalls can route. The difference is focus: a router is built to forward packets fast, a firewall is built to inspect and control them, and it remembers each conversation.