{"id":947,"date":"2025-12-19T10:49:49","date_gmt":"2025-12-19T09:49:49","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=947"},"modified":"2026-05-30T00:59:50","modified_gmt":"2026-05-29T22:59:50","slug":"what-is-a-firewall","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-a-firewall\/","title":{"rendered":"What is a firewall?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">In network security, systems engineering, and cloud infrastructure management, maintaining a hardened perimeter is a baseline operational standard. A <strong>firewall<\/strong> (or network firewall) is a specialized security system\u2014implemented as software, dedicated hardware, or a hybrid cloud service\u2014engineered to systematically monitor, filter, and control incoming and outgoing network traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By operating as an inline gatekeeper positioned between a trusted internal network (such as a private corporate intranet) and an untrusted external network (such as the public internet), a firewall blocks unauthorized access vectors and thwarts malicious exploits before they can penetrate deeper system layers.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-a-firewall\/#Core_Operational_Mechanics_Allow_Reject_and_Drop\" >Core Operational Mechanics: Allow, Reject, and Drop<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-a-firewall\/#Structural_Classifications_of_Firewall_Architectures\" >Structural Classifications of Firewall Architectures<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Core_Operational_Mechanics_Allow_Reject_and_Drop\"><\/span>Core Operational Mechanics: Allow, Reject, and Drop<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<\/div>\n\n<div id=\"mybox-3018656039\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A firewall evaluates every single packet of data that attempts to cross its interface boundary. This evaluation relies entirely on a pre-configured matrix of <strong>Access Control Lists (ACLs)<\/strong> and security rules defined by network administrators. When a data packet hits the firewall, the system matches the packet&#8217;s metadata against these rules and executes one of three core actions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Allow (Accept):<\/strong> The data packet perfectly aligns with established security criteria (e.g., traffic originating from a verified internal IP address targeting an authorized port). The firewall opens the gate and forwards the packet cleanly along its routing path.<\/li>\n\n\n\n<li><strong>Reject:<\/strong> The data packet violates a security rule (e.g., an unauthenticated external terminal attempting to connect to an internal database port). The firewall blocks the packet from entering the network and actively transmits an error payload\u2014such as an ICMP &#8220;Destination Unreachable&#8221; frame\u2014back to the sender, explicitly informing them that the connection was refused.<\/li>\n\n\n\n<li><strong>Drop:<\/strong> The packet is flagged as highly suspicious, malicious, or part of an active port scan or distributed attack. The firewall blocks the data but <strong>sends no response<\/strong> back to the source. The packet simply ceases to exist on the wire. This silent blocking technique hides your active ports, leaving attackers in the dark about whether a server even exists at that address.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Structural_Classifications_of_Firewall_Architectures\"><\/span>Structural Classifications of Firewall Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Firewall technology scales across several operational models depending on which layer of the network protocol stack it needs to inspect:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. Packet Filtering Firewalls (Stateless Architecture)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The most basic, legacy form of network defense. It inspects individual data packets in complete isolation at <strong>Layer 3 (Network)<\/strong> and <strong>Layer 4 (Transport)<\/strong> of the OSI model. It checks basic header parameters\u2014such as source IP, destination IP, protocol type, and target port numbers\u2014against static rule tables. Because it does not remember past packets or track the overall connection state, it is highly performant but vulnerable to spoofing attacks.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. Stateful Inspection Firewalls<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A more advanced configuration that actively tracks the state of running network connections. It maintains a dynamic <strong>State Table<\/strong> to remember open communication channels (like an active TCP three-way handshake). When a packet arrives, the firewall verifies if it belongs to an already established, trusted conversation loop. If the packet arrives out of sequence or lacks a valid matching state entry, the firewall flags it as an anomaly and drops it instantly.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3. Web Application Firewalls (WAF)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Engineered specifically to protect software applications at <strong>Layer 7 (Application Layer)<\/strong>. Rather than focusing purely on IP addresses or port numbers, a WAF executes deep packet inspection on the actual payload data inside HTTP and HTTPS requests. It analyzes URL parameters, form inputs, and cookie headers to block web-specific exploits like SQL Injections (SQLi) and Cross-Site Scripting (XSS).<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[25],"manual_kb_tag":[1039,1040,1041,1042,1043,1044,1045,1046,205,444,990,1034,1035,1036,1037,1038],"class_list":["post-947","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-hosting","manual_kb_tag-security-software","manual_kb_tag-security-hardware","manual_kb_tag-internal-networks","manual_kb_tag-external-networks","manual_kb_tag-private-networks","manual_kb_tag-unauthorized-access","manual_kb_tag-security-rules","manual_kb_tag-traffic-monitoring","manual_kb_tag-hardware","manual_kb_tag-access-control","manual_kb_tag-network-security","manual_kb_tag-firewall","manual_kb_tag-network-firewall","manual_kb_tag-network-traffic","manual_kb_tag-incoming-traffic","manual_kb_tag-outgoing-traffic"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/947\/revisions"}],"predecessor-version":[{"id":8981,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/947\/revisions\/8981"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=947"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=947"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}