Skip to main content

Firewall

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/firewall

In short

A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.

What is a firewall?

A firewall is a hardware device or piece of software that controls which network traffic is allowed into or out of a computer or network. It checks each connection against a list of rules, for example allowing web traffic on port 443 while blocking everything else. Its goal is to keep unwanted or malicious traffic away from systems that should not be exposed.

Rules usually match on properties such as the source and destination IP address, the port number, the protocol (TCP or UDP), and the direction of traffic. A simple packet-filtering firewall looks at each packet on its own, while a stateful firewall tracks open connections, so replies to requests you made are allowed back in automatically. Web application firewalls (WAFs) go further, inspecting the content of HTTP requests to detect attacks such as SQL injection.

A firewall works like a security guard at a building entrance who checks everyone against a guest list. Firewalls are everywhere: built into operating systems and home routers, placed at the edge of company networks, and offered in the cloud as security groups or network rules that decide which servers can talk to each other. A good practice is to deny everything by default and open only the ports a service really needs.

A firewall is not a complete security solution. It cannot stop an attacker who uses an allowed path, such as a vulnerable web app on port 443, or a user who installs malware from a phishing email. It is also different from a VPN: a firewall decides which traffic is allowed, while a VPN encrypts traffic and creates a private tunnel between networks.

Key takeaways

  • A firewall allows or blocks network traffic according to rules.
  • Rules typically match on IP address, port, protocol, and traffic direction.
  • Stateful firewalls track connections and automatically allow replies to outgoing requests.
  • A default-deny policy that opens only the needed ports is a common best practice.
  • Firewalls are one layer of defense and do not replace secure code or authentication.

Example

Setting basic firewall rules on Linux with ufwbash
# Block all incoming traffic by default, allow outgoing
sudo ufw default deny incoming
sudo ufw default allow outgoing

# Allow SSH and HTTPS only
sudo ufw allow 22/tcp
sudo ufw allow 443/tcp

# Turn the firewall on and review the rules
sudo ufw enable
sudo ufw status verbose

Readers ask

What is the difference between a firewall and antivirus software?

A firewall controls which network traffic can reach or leave a device, while antivirus software scans files and programs on the device for malware. They protect against different threats and are usually used together.

What is a web application firewall (WAF)?

A WAF is a firewall that inspects HTTP requests to a web application and blocks ones that look like attacks, such as SQL injection or cross-site scripting. It works at the application level, while a traditional firewall mostly looks at IP addresses and ports.

Do I need a firewall on a cloud server?

Yes. Cloud platforms usually provide network-level rules, often called security groups, and you should allow only the ports your service needs, such as 443 for HTTPS and 22 for SSH from trusted addresses.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings