{"id":467,"date":"2025-12-18T07:55:53","date_gmt":"2025-12-18T06:55:53","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=467"},"modified":"2026-06-07T19:55:11","modified_gmt":"2026-06-07T17:55:11","slug":"how-does-a-firewall-work","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/","title":{"rendered":"How does a firewall work?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A firewall is a security system that monitors and controls network traffic entering and leaving a device, server, or network. Its primary purpose is to allow legitimate communication while blocking unauthorized or potentially malicious traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Firewalls can be implemented as software, hardware, or a combination of both.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#What_Is_a_Firewall\" >What Is a Firewall?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#How_a_Firewall_Works\" >How a Firewall Works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Outgoing_Traffic\" >Outgoing Traffic<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Incoming_Traffic\" >Incoming Traffic<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#What_Information_Does_a_Firewall_Analyze\" >What Information Does a Firewall Analyze?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Source\" >Source<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Destination\" >Destination<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Port\" >Port<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Protocol\" >Protocol<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Content\" >Content<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Common_Firewall_Actions\" >Common Firewall Actions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Allow\" >Allow<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Deny\" >Deny<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Drop\" >Drop<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Log\" >Log<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Example\" >Example<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Why_Firewalls_Are_Important\" >Why Firewalls Are Important<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-a-firewall-work\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Is_a_Firewall\"><\/span>What Is a Firewall?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-1616227624\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A firewall acts as a barrier between a trusted network and untrusted networks, such as the Internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every connection attempt is evaluated against a predefined set of security rules before access is granted or denied.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_a_Firewall_Works\"><\/span>How a Firewall Works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A firewall maintains a collection of rules that determine which traffic is allowed and which traffic should be blocked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When network traffic reaches the firewall, it compares the connection details against these rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the traffic matches an allowed rule:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Access Granted\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the traffic violates a rule or matches a blocked condition:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Access Denied\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The firewall performs this analysis for both incoming and outgoing connections.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Outgoing_Traffic\"><\/span>Outgoing Traffic<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Outgoing traffic originates from the server, computer, or application protected by the firewall.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Accessing a website<\/li>\n\n\n\n<li>Sending an email<\/li>\n\n\n\n<li>Connecting to an external API<\/li>\n\n\n\n<li>Downloading updates<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By default, many firewall configurations allow most outgoing traffic, although this behavior can be customized.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Incoming_Traffic\"><\/span>Incoming Traffic<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Incoming traffic originates from external devices attempting to connect to the protected system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Visitors accessing a website<\/li>\n\n\n\n<li>Incoming email delivery<\/li>\n\n\n\n<li>Remote administration connections<\/li>\n\n\n\n<li>Application requests<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Incoming traffic is generally subject to stricter filtering.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Information_Does_a_Firewall_Analyze\"><\/span>What Information Does a Firewall Analyze?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To decide whether traffic should be allowed or blocked, a firewall examines several attributes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Source\"><\/span>Source<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The originating IP address or network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>192.168.1.100\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Destination\"><\/span>Destination<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The target IP address or service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>203.0.113.10\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Port\"><\/span>Port<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The network port being accessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common examples:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Port<\/th><th>Service<\/th><\/tr><\/thead><tbody><tr><td>80<\/td><td>HTTP<\/td><\/tr><tr><td>443<\/td><td>HTTPS<\/td><\/tr><tr><td>21<\/td><td>FTP<\/td><\/tr><tr><td>22<\/td><td>SSH<\/td><\/tr><tr><td>25<\/td><td>SMTP<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Protocol\"><\/span>Protocol<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The communication protocol being used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common protocols include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>TCP<\/li>\n\n\n\n<li>UDP<\/li>\n\n\n\n<li>ICMP<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Content\"><\/span>Content<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some advanced firewalls can inspect packet contents to identify:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Malware<\/li>\n\n\n\n<li>Exploit attempts<\/li>\n\n\n\n<li>Suspicious commands<\/li>\n\n\n\n<li>Unauthorized applications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_Firewall_Actions\"><\/span>Common Firewall Actions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A firewall typically performs one of the following actions:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Allow\"><\/span>Allow<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The connection is permitted.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Deny\"><\/span>Deny<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The connection is blocked and rejected.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Drop\"><\/span>Drop<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The connection is silently discarded without responding.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Log\"><\/span>Log<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Information about the connection attempt is recorded for monitoring and analysis.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Example\"><\/span>Example<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose a server hosts a website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Firewall rules might allow:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TCP Port 80 (HTTP)\nTCP Port 443 (HTTPS)\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">and block:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>All other incoming ports\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">As a result:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Website visitors can access the site normally.<\/li>\n\n\n\n<li>Unauthorized attempts to connect to other services are blocked.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Firewalls_Are_Important\"><\/span>Why Firewalls Are Important<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A firewall helps protect systems against:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Unauthorized access<\/li>\n\n\n\n<li>Brute-force attacks<\/li>\n\n\n\n<li>Malware communication<\/li>\n\n\n\n<li>Network scanning<\/li>\n\n\n\n<li>Denial-of-service attempts<\/li>\n\n\n\n<li>Exploitation of vulnerable services<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It serves as one of the first lines of defense in a layered security strategy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A firewall monitors incoming and outgoing network traffic and evaluates it against predefined security rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It makes decisions based on factors such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Source IP address<\/li>\n\n\n\n<li>Destination IP address<\/li>\n\n\n\n<li>Port number<\/li>\n\n\n\n<li>Protocol<\/li>\n\n\n\n<li>Traffic content<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If the traffic complies with the configured rules, it is allowed. Otherwise, it is blocked, helping protect servers, websites, and networks from unauthorized access and malicious activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[25],"manual_kb_tag":[444,990,1034,1359,3122,3123,3124,3125,3126,3127],"class_list":["post-467","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-hosting","manual_kb_tag-access-control","manual_kb_tag-network-security","manual_kb_tag-firewall","manual_kb_tag-traffic-filtering","manual_kb_tag-firewall-rules","manual_kb_tag-inbound-traffic","manual_kb_tag-outbound-traffic","manual_kb_tag-packet-inspection","manual_kb_tag-content-inspection","manual_kb_tag-port-filtering"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":4,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/467\/revisions"}],"predecessor-version":[{"id":4963,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/467\/revisions\/4963"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=467"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=467"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}