The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

What Is a Firewall?

A firewall is a network security system that monitors and controls incoming and outgoing traffic based on defined rules. It helps prevent unauthorized connections while allowing approved traffic to pass.

Why are firewalls important?

Firewalls help organizations control how systems communicate across network boundaries. By evaluating traffic before it reaches its destination, a firewall can reduce unwanted access and enforce rules about which connections are permitted.

As a foundational part of network security, firewalls can help teams:

  • Limit unauthorized access by blocking connections that do not meet established security rules.
  • Control inbound and outbound traffic between internal systems, external networks, and different security zones.
  • Reduce network exposure by restricting unnecessary ports, protocols, services, or connections.
  • Enforce security policies consistently across network boundaries.
  • Support network segmentation by controlling communication between different parts of an environment.

A firewall is one security control, not a complete defense against every cyberattack. Organizations typically use firewalls alongside monitoring, detection and response, endpoint security, application security, and other controls.

How does a firewall work?

A firewall sits at a point where network traffic can be inspected and controlled. Depending on the type of firewall, that might be between an internal network and the internet, between network segments, or directly on an individual device.

The basic process typically involves inspecting traffic, comparing it with security rules, and deciding what should happen next.

1. Inspect network traffic

Network communications are transmitted in packets. A firewall can examine information associated with those packets or connections, such as:

  • Source and destination IP addresses
  • Source and destination ports
  • Network protocol
  • Connection state
  • In some firewall types, application or traffic characteristics

How deeply a firewall inspects traffic depends on its capabilities. A basic packet-filtering firewall evaluates less context than a stateful or application-aware firewall.

2. Apply firewall rules

The firewall compares the traffic with configured rules, sometimes called firewall policies. These rules define which types of communication are permitted or restricted.

For example, an organization might allow employees to access a required service while denying unsolicited connections from an untrusted network. Rules can also limit communication between internal network segments.

3. Allow or block the traffic

After applying its rules, the firewall takes an action: It may allow the traffic to continue, deny or drop it, or log the activity for monitoring and investigation.

Logging is particularly useful because firewall activity can provide security teams with context about connections that were attempted, permitted, or blocked.

What are the main types of firewalls?

“Firewall” describes a broad category of security technology rather than one specific architecture. Different types inspect different information, operate in different locations, or provide different levels of traffic awareness.

Packet-filtering firewalls

Packet-filtering firewalls evaluate individual packets using information such as IP addresses, ports, and protocols. They apply predefined rules to determine whether traffic should be allowed or blocked.

This approach provides basic traffic control but has limited context about the broader connection or application generating the traffic.

Stateful inspection firewalls

Stateful firewalls track the state of active network connections rather than evaluating every packet in isolation. They can determine whether a packet belongs to an established or expected connection and use that context when making filtering decisions.

Proxy and application-layer firewalls

A proxy firewall acts as an intermediary between communicating systems. Instead of allowing systems to communicate directly, the proxy receives traffic and passes permitted communication to its destination.

Application-layer inspection can also evaluate information associated with particular applications or protocols, providing more context than basic packet filtering.

Next-generation firewalls

Next-generation firewalls (NGFWs) extend traditional firewall functions with deeper traffic inspection and additional security capabilities. The specific capabilities vary by implementation, but NGFWs commonly provide greater visibility into applications and network activity than traditional packet-filtering firewalls.

Related approaches such as unified threat management combine multiple network security functions within a broader system.

Host-based firewalls

A host-based or software firewall runs on an individual computer, server, or other endpoint. Instead of protecting an entire network boundary, it controls traffic entering or leaving that particular system.

Host-based controls can complement network firewalls by applying policies closer to individual workloads and devices.

Web application firewalls

A web application firewall (WAF) is a specialized firewall designed to inspect and filter traffic to web applications. WAFs focus on application-layer web traffic and can help defend against threats such as SQL injection and cross-site scripting (XSS).

That makes a WAF different from a general network firewall. Network firewalls primarily control communication between networks, systems, or security zones, while WAFs specialize in protecting web applications and their HTTP-based traffic.

How do firewalls fit into network security?

Firewalls can operate at several points in an environment, depending on what traffic an organization needs to control. Their role is often less about creating a single perimeter and more about enforcing boundaries between systems that should have different levels of access.

Some of the more common use cases include:

  • Internet perimeter: A firewall controls connections between an organization's network and external networks such as the internet.
  • Network segmentation: Firewalls can enforce network segmentation by limiting which systems or network zones can communicate with each other.
  • Endpoint protection: Host-based firewalls control connections to and from individual computers, servers, or workloads.
  • Application protection: Specialized controls such as WAFs inspect web application traffic for application-specific threats.

Firewall data can also contribute to broader security monitoring. For example, network traffic analysis examines network activity to identify patterns and potentially suspicious behavior, while a firewall primarily enforces policies about which traffic is permitted.

These capabilities are complementary, as a firewall can block a connection based on its rules, while other security controls can help teams understand activity across endpoints, identities, applications, and networks and then investigate behavior that requires additional context.

Author

Aaron Wells
Aaron Wells

Frequently asked questions