A firewall is a security system that monitors and controls network traffic entering and leaving a device, server, or network. Its primary purpose is to allow legitimate communication while blocking unauthorized or potentially malicious traffic.
Firewalls can be implemented as software, hardware, or a combination of both.
Table of Contents
What Is a Firewall?
A firewall acts as a barrier between a trusted network and untrusted networks, such as the Internet.
Every connection attempt is evaluated against a predefined set of security rules before access is granted or denied.
How a Firewall Works
A firewall maintains a collection of rules that determine which traffic is allowed and which traffic should be blocked.
When network traffic reaches the firewall, it compares the connection details against these rules.
If the traffic matches an allowed rule:
Access Granted
If the traffic violates a rule or matches a blocked condition:
Access Denied
The firewall performs this analysis for both incoming and outgoing connections.
Outgoing Traffic
Outgoing traffic originates from the server, computer, or application protected by the firewall.
Examples:
- Accessing a website
- Sending an email
- Connecting to an external API
- Downloading updates
By default, many firewall configurations allow most outgoing traffic, although this behavior can be customized.
Incoming Traffic
Incoming traffic originates from external devices attempting to connect to the protected system.
Examples:
- Visitors accessing a website
- Incoming email delivery
- Remote administration connections
- Application requests
Incoming traffic is generally subject to stricter filtering.
What Information Does a Firewall Analyze?
To decide whether traffic should be allowed or blocked, a firewall examines several attributes.
Source
The originating IP address or network.
Example:
192.168.1.100
Destination
The target IP address or service.
Example:
203.0.113.10
Port
The network port being accessed.
Common examples:
| Port | Service |
|---|---|
| 80 | HTTP |
| 443 | HTTPS |
| 21 | FTP |
| 22 | SSH |
| 25 | SMTP |
Protocol
The communication protocol being used.
Common protocols include:
- TCP
- UDP
- ICMP
Content
Some advanced firewalls can inspect packet contents to identify:
- Malware
- Exploit attempts
- Suspicious commands
- Unauthorized applications
Common Firewall Actions
A firewall typically performs one of the following actions:
Allow
The connection is permitted.
Deny
The connection is blocked and rejected.
Drop
The connection is silently discarded without responding.
Log
Information about the connection attempt is recorded for monitoring and analysis.
Example
Suppose a server hosts a website.
Firewall rules might allow:
TCP Port 80 (HTTP)
TCP Port 443 (HTTPS)
and block:
All other incoming ports
As a result:
- Website visitors can access the site normally.
- Unauthorized attempts to connect to other services are blocked.
Why Firewalls Are Important
A firewall helps protect systems against:
- Unauthorized access
- Brute-force attacks
- Malware communication
- Network scanning
- Denial-of-service attempts
- Exploitation of vulnerable services
It serves as one of the first lines of defense in a layered security strategy.
Summary
A firewall monitors incoming and outgoing network traffic and evaluates it against predefined security rules.
It makes decisions based on factors such as:
- Source IP address
- Destination IP address
- Port number
- Protocol
- Traffic content
If the traffic complies with the configured rules, it is allowed. Otherwise, it is blocked, helping protect servers, websites, and networks from unauthorized access and malicious activity.