Firewall
- In Turkish
- Güvenlik Duvarı
In short
A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
What is a firewall?
A firewall is a hardware device or piece of software that controls which network traffic is allowed into or out of a computer or network. It checks each connection against a list of rules, for example allowing web traffic on port 443 while blocking everything else. Its goal is to keep unwanted or malicious traffic away from systems that should not be exposed.
Rules usually match on properties such as the source and destination IP address, the port number, the protocol (TCP or UDP), and the direction of traffic. A simple packet-filtering firewall looks at each packet on its own, while a stateful firewall tracks open connections, so replies to requests you made are allowed back in automatically. Web application firewalls (WAFs) go further, inspecting the content of HTTP requests to detect attacks such as SQL injection.
A firewall works like a security guard at a building entrance who checks everyone against a guest list. Firewalls are everywhere: built into operating systems and home routers, placed at the edge of company networks, and offered in the cloud as security groups or network rules that decide which servers can talk to each other. A good practice is to deny everything by default and open only the ports a service really needs.
A firewall is not a complete security solution. It cannot stop an attacker who uses an allowed path, such as a vulnerable web app on port 443, or a user who installs malware from a phishing email. It is also different from a VPN: a firewall decides which traffic is allowed, while a VPN encrypts traffic and creates a private tunnel between networks.
Key takeaways
- A firewall allows or blocks network traffic according to rules.
- Rules typically match on IP address, port, protocol, and traffic direction.
- Stateful firewalls track connections and automatically allow replies to outgoing requests.
- A default-deny policy that opens only the needed ports is a common best practice.
- Firewalls are one layer of defense and do not replace secure code or authentication.
Example
# Block all incoming traffic by default, allow outgoing
sudo ufw default deny incoming
sudo ufw default allow outgoing
# Allow SSH and HTTPS only
sudo ufw allow 22/tcp
sudo ufw allow 443/tcp
# Turn the firewall on and review the rules
sudo ufw enable
sudo ufw status verboseReaders ask
What is the difference between a firewall and antivirus software?
A firewall controls which network traffic can reach or leave a device, while antivirus software scans files and programs on the device for malware. They protect against different threats and are usually used together.
What is a web application firewall (WAF)?
A WAF is a firewall that inspects HTTP requests to a web application and blocks ones that look like attacks, such as SQL injection or cross-site scripting. It works at the application level, while a traditional firewall mostly looks at IP addresses and ports.
Do I need a firewall on a cloud server?
Yes. Cloud platforms usually provide network-level rules, often called security groups, and you should allow only the ports your service needs, such as 443 for HTTPS and 22 for SSH from trusted addresses.
See also
- PortNetworking, p. 22A port is a number from 0 to 65535 that identifies a specific program or service on a device, so traffic reaching an IP address gets to the right application.
- IP AddressNetworking, p. 10An IP address is a numeric label assigned to each device on a network so that data can be routed to it, much like a postal address for a house.
- VPNNetworking, p. 36A VPN is a technology that creates an encrypted tunnel between a device and another network, so traffic can travel privately across the public internet.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- DDoSSecurity, p. 10A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
- PacketNetworking, p. 20A packet is a small, formatted unit of data sent across a network, made of a header with addressing information and a payload that carries the actual data.
- Web Application FirewallSecurity, p. 47A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
Spotted a mistake or something missing on this page?Suggest an edit