A firewall is a device (or software) that checks network traffic and decides whether to allow it or block it, following a list of rules written by an administrator. The name comes from buildings: a firewall is a wall that stops a fire spreading from one part of a building to another.
💡 In simple terms: a firewall is the security desk at the entrance of an office building. Staff walk out freely and come back in. Visitors are only let in if they are expected and are going to an allowed place. Everyone else is turned away, and the desk writes it all down in a logbook.
Why firewalls exist
A router's job is to deliver packets. If it knows a route, it forwards the packet. It doesn't ask whether the packet should be delivered. That is a problem when one side of the router is the internet: millions of machines scan the internet all day looking for open doors. A firewall adds the missing question: is this traffic allowed?
- Keep unwanted traffic from the internet out of the private network.
- Control what inside users and devices can reach outside.
- Separate parts of a network that need different levels of trust, such as guests, staff and servers.
- Record what was allowed and blocked, for troubleshooting and security investigations.
Where a firewall sits
At the edge
The most common place is the network edge: the point where the private network meets the internet. All traffic in and out must pass through it, so it is the natural checkpoint.
- 1. A staff PC opens a website. Inside-to-outside web traffic is allowed by the rules, so the firewall passes it and remembers the conversation.
- 2. The reply is let back in. It belongs to a conversation the PC started, so the firewall lets it through.
- 3. A scanner tries the file server. Nobody inside asked for this, and no rule allows it. The firewall drops it and logs it.
Between zones
Firewalls group interfaces into zones, each with a trust level. Rules then say what may pass from one zone to another. A common design has three zones:
Outside (untrusted)
The internet. Nothing from here is trusted by default.
DMZ (semi-trusted)
Servers the public must reach, such as a web server. If one is broken into, the attacker is still not inside the main network.
Inside (trusted)
Staff PCs, internal servers, printers. The most protected zone.
- 1. A customer opens the website. Outside → DMZ on TCP 443 is allowed, so it reaches the web server.
- 2. The web server queries the database. A specific rule allows the web server, and only the web server, to reach the database's port.
- 3. The customer tries the database directly. Outside → inside is not allowed. Blocked.
- 4. Staff manage the web server. Inside → DMZ is allowed, so staff can update the site.
Larger networks also put firewalls inside the network, for example between the guest Wi-Fi and the office, or in front of the finance servers. Splitting a network this way is covered in Network segmentation.
Network firewalls and host firewalls
| Network firewall | Host firewall | |
|---|---|---|
| What it is | A dedicated device (or virtual appliance) on the network path | Software on one computer, e.g. Windows Defender Firewall, ufw on Linux |
| Protects | Everything behind it | Only the device it runs on |
| Sees | Only traffic that crosses it | All traffic to and from that device, including from the same LAN |
| Managed by | Network or security team | The device owner, or IT through central policies |
| Example | Office edge firewall | A laptop on café Wi-Fi blocking file sharing |
Use both. They protect against different things. This idea of several layers of protection is called defence in depth; see Basic network security.
Firewalls also come in other forms: a feature inside a home router, a virtual firewall running on a server, and cloud firewalls (security groups) that protect cloud servers, covered in Cloud networking basics.
Important parts of a firewall
| Part | What it does |
|---|---|
| Interfaces and zones | Each network port connects to a network, and belongs to a zone such as inside, outside or DMZ |
| Rule table (policy) | An ordered list: which source, destination and service is allowed or denied |
| Connection (state) table | The firewall's memory of conversations in progress, so replies can come back |
| Logs | A record of allowed and blocked connections |
| Management | A web page, command line or central manager for rules and monitoring |
How a firewall decides, in brief
Two ideas matter here. First, a rule list usually ends with an invisible deny everything else: if no rule allows something, it is blocked. Second, modern firewalls are stateful: they remember each conversation started from inside and automatically let its replies back in, without a separate rule. Writing rules and how stateful inspection works are taught in Firewall basics.
What a firewall looks at in a packet
A traditional firewall reads the IP header and the TCP or UDP header. That gives it five facts, often called the 5-tuple:
| Field | Example | Comes from |
|---|---|---|
| Source IP | 198.51.100.25 | IP header (Layer 3) |
| Destination IP | 203.0.113.10 | IP header (Layer 3) |
| Protocol | TCP | IP header (Layer 3) |
| Source port | 51514 | TCP header (Layer 4) |
| Destination port | 443 (HTTPS) | TCP header (Layer 4) |
The destination port tells the firewall which service is wanted: 443 for HTTPS, 22 for SSH, 3389 for Remote Desktop. See Common ports to know. Edge firewalls very often do NAT too, so the addresses can change as the packet passes through.
Next-generation firewalls
Port numbers are a weak clue. Almost everything now runs over port 443, and any program can use any port. A next-generation firewall (NGFW) looks deeper, into the application data itself (Layer 7). It adds features such as:
- Application awareness: it recognises the actual app (a video service, a file-sharing tool) whatever port it uses, and can allow one and block another.
- User identity: rules by person or group ("Finance may use the banking app") instead of only by IP address.
- Intrusion prevention (IPS): it spots known attack patterns in traffic and blocks them.
- URL filtering and malware scanning: it blocks known bad websites and checks downloads.
- TLS inspection: with the organisation's own certificate installed on devices, it can decrypt and inspect encrypted traffic. This is powerful but raises privacy questions.
| OSI layer | RouterIP addresses | FirewallIPs + ports | NGFW+ applications |
|---|---|---|---|
| L7 ApplicationHTTP, DNS | – | – | ✓ |
| L6 PresentationEncoding, encryption | – | – | some |
| L5 SessionSessions | – | – | some |
| L4 TransportTCP/UDP ports | – | ✓ | ✓ |
| L3 NetworkIP addresses | ✓ | ✓ | ✓ |
| L2 Data LinkFrames, MAC addresses | ✓ | ✓ | ✓ |
| L1 PhysicalBits on cable or radio | ✓ | ✓ | ✓ |
A real-world example: the home router
Your home router contains a simple firewall. When your laptop (192.168.1.20) opens a website, the router records the conversation and lets the replies back in. When a stranger on the internet sends a connection attempt to your public address 203.0.113.45, the router has no matching conversation and no rule allowing it, so it drops it. That is why your printer and smart TV are not reachable from the internet, unless you open a door yourself with port forwarding.
- 1. The laptop opens a website. Outbound traffic is allowed. The router notes the conversation in its state table.
- 2. The reply matches the conversation. It comes back to 203.0.113.45 and is passed to the laptop.
- 3. A stranger tries to reach the printer. No conversation and no port-forward rule match, so the home router drops it.
⚠️ Every port-forwarding rule you add is a hole in that firewall. Only forward what you really need, and remove rules you no longer use.
When a firewall causes problems
| Symptom | Likely cause | What to check |
|---|---|---|
| Ping works but an application doesn't connect | The firewall allows ICMP but blocks the app's port | Test the exact port; check the firewall logs |
| Connection hangs, then times out | Traffic is silently dropped | Logs on the network firewall and the host firewall |
| Connection refused instantly | Usually no program listening, or a firewall sending a reject | Is the service running? Is a reject rule in place? |
| Works from inside, not from the internet | No inbound rule or port forward | Edge firewall rules and NAT |
| Everything stops when the firewall fails | The firewall is a single point of failure on the path | Hardware status; businesses use a pair of firewalls for this reason |
A firewall that crashes usually fails closed: it blocks everything rather than letting everything through. That is safer, but it means a firewall outage is a network outage.
Useful commands
Check whether the host firewall is on:
C:\>netsh advfirewall show allprofiles state Domain Profile Settings: ---------------------------------------------------------------------- State ON Private Profile Settings: ---------------------------------------------------------------------- State ON Public Profile Settings: ---------------------------------------------------------------------- State ON Ok.
$ sudo ufw status verbose Status: active Logging: on (low) Default: deny (incoming), allow (outgoing), disabled (routed) New profiles: skip To Action From -- ------ ---- 22/tcp ALLOW IN 192.168.10.0/24 443/tcp ALLOW IN Anywhere
Incoming traffic is denied by default. SSH is allowed only from the office LAN, and HTTPS from anywhere.
Test whether a particular port gets through, end to end:
PS C:\>Test-NetConnection 192.168.10.20 -Port 445 WARNING: TCP connect to (192.168.10.20 : 445) failed ComputerName : 192.168.10.20 RemoteAddress : 192.168.10.20 RemotePort : 445 InterfaceAlias : Ethernet SourceAddress : 192.168.10.11 PingSucceeded : True TcpTestSucceeded : False
Ping succeeds but TCP 445 fails: the server is reachable, so something (very often a firewall) is blocking that port. To test a public address from outside, try the Port Checker.
Common mistakes
- Thinking “ping works” means the firewall allows everything. Firewalls filter per protocol and port.
- Forgetting the host firewall. The network firewall allows the traffic, but Windows Firewall on the server blocks it.
- Turning the firewall off “just to test” and forgetting to turn it back on.
- Opening a port to “Anywhere” when only a few addresses need it.
- Believing a firewall makes a network safe on its own. It is one layer of protection among several.
- A firewall allows or blocks traffic based on rules; anything not allowed is denied.
- It usually sits at the edge between the LAN and the internet, and can also separate internal zones such as a DMZ.
- Network firewalls protect everything behind them; host firewalls protect one device everywhere it goes.
- Traditional firewalls decide on IPs, protocol and ports (Layers 3–4); NGFWs also understand applications (Layer 7).
- Stateful firewalls let replies to inside-initiated traffic back in automatically.
Knowledge check
A company wants customers on the internet to reach its web server, but never its internal database. Where should the web server go?
Your laptop is on café Wi-Fi. Which firewall protects it from other people on that Wi-Fi?
A rule allows TCP 443 to the web server. A packet arrives for TCP 3389 (Remote Desktop) on the same server, and no other rule matches.
Staff use a chat app over HTTPS (port 443). Management wants to block that app but keep normal websites working. What is needed?
Where to go next
You'll write firewall rules and see stateful inspection in action in Firewall basics. Next in this unit: Wireless access points.