What a Firewall Does — and What It Doesn’t
A firewall is a security system that controls network traffic according to a set of rules.
Think of it like a security checkpoint.
Instead of allowing every connection into or out of a system, the firewall examines traffic and decides whether it should be allowed or blocked.
How Does a Firewall Work?
When network traffic reaches a firewall, it can evaluate information such as:
- Source IP address
- Destination IP address
- Port
- Protocol
- Connection state
- Configured security rules
For example, a firewall might have a rule such as:
Allow: HTTPS traffic
Block: Unwanted inbound connections
The exact rules depend on the system and its security requirements.
What Can a Firewall Do?
A firewall can help:
- Block unauthorized network connections.
- Restrict access to specific ports.
- Control inbound and outbound traffic.
- Reduce exposure to unwanted network activity.
- Enforce an organization’s network security rules.
What Can’t a Firewall Do?
A firewall is not a complete security solution.
For example, it cannot automatically protect you from:
- A user giving away their password.
- A phishing attack that tricks someone into clicking a link.
- Malware that is already allowed to communicate.
- Weak passwords.
- An attacker who gains legitimate access to an account.
This is why cybersecurity uses multiple layers of defense rather than relying on a single tool.
A Simple Example
Imagine a company has a server that should only accept HTTPS connections.
The firewall could allow:
Port 443 → Allowed
while blocking unnecessary inbound services.
This reduces the number of network services exposed to the internet.
Key Takeaways
- A firewall controls network traffic using rules.
- It can block unwanted or unauthorized connections.
- Firewalls can protect both individual devices and entire networks.
- A firewall cannot stop every type of cyberattack.
- Good security uses multiple layers of protection.
Try It Yourself
If you use Linux, you can explore your firewall configuration with tools such as:
sudo ufw status
Don’t change firewall rules on a system you don’t own or administer. Use your own virtual machine or lab environment for practice.
