A firewall decides which traffic may pass between two networks, by matching each packet against an ordered list of rules where the first match wins. It also keeps a table of connections it has already allowed, so replies to outbound requests pass without a rule of their own.
- First matching rule wins, nothing below is read
- The last rule should deny everything
- Stateful means replies need no inbound rule
- Drop outward, reject inward
- It cannot read encrypted traffic it does not terminate
On this page
- How a rule is actually evaluated
- Stateful, and why it changed everything
- The kinds, in the order they arrived
- Network based, host based, cloud based
- Threat prevention, and what it is really worth
- What a firewall actually stops
- What a firewall does not do
- What auditors and insurers ask about
- Rules that stay maintainable
- Comparison
- FAQ
The rulesHow a rule is actually evaluated
A firewall holds an ordered list of rules. For each packet the firewall works down the list, and the first rule that matches decides the outcome. Nothing below that rule is consulted.
That ordering is the whole discipline of firewall filtering. A permissive rule placed above a restrictive one makes the restrictive one dead, and the firewall will not warn you.
Reviewing a rule set means reading it in order, not reading it as a set of independent statements, and it is why a rule that appears to do nothing is usually sitting below one that already matched.
A rule matches packets on some combination of five things, which is why the phrase five tuple appears everywhere: source address, destination address, source port, destination port, and protocol. Each field can be a single value, a range, a named group, or any.
The outcome is one of three, and the difference between the last two is worth knowing.
Allow lets the packet through.
Drop discards the packet silently. The sender learns nothing and waits for a timeout, which is slow for them and quiet for you. This is the right default facing the internet, because it gives a network scanner no information.
Reject discards it and sends back a message saying so. The sender fails immediately, which is much kinder on an internal network where the sender is a colleague waiting for a connection that will never happen.
The last rule in any well built set is a deny for everything, and the rules above it are the exceptions. Building the other way round, permitting everything and blocking known bad things, produces a firewall that is only as good as the list of things somebody thought of.
StateStateful, and why it changed everything
The first firewalls did packet filtering, examining each packet alone. That works for blocking and is painful for allowing, because every conversation has two directions.
A user requests a web page. The request leaves on port 443 to a server. The answer comes back from that server, from port 443, to a high numbered port on the user's machine.
A firewall with no memory cannot tell that answer apart from an unsolicited connection, so allowing it means allowing anything from port 443 to any high port, inbound, which is close to allowing everything.
Stateful inspection solved that. The firewall keeps a table of network connections it has permitted, holding the addresses, the ports and the state of each one.
When a packet arrives the firewall checks that table first: if it belongs to a connection already allowed, it passes without consulting a single rule. Only packets that start something new are evaluated against the rule set.
Two consequences follow, and both show up in practice.
Rules become one directional. You write a rule permitting the outbound request. The reply is handled by the state table, and no inbound rule is needed. A rule set full of matching inbound rules is usually a sign that someone did not trust the state table.
The state table is a resource. Every connection the firewall tracks uses memory, and each device has a maximum. A flood of half opened connections can fill it, at which point new legitimate connections are refused. That is a denial of service against the firewall rather than against anything behind it.
The generationsThe kinds, in the order they arrived
The vocabulary is layered by history, and each generation kept the previous one inside it.
Packet filtering firewalls examine one packet at a time against addresses and ports, with no memory of earlier packets. Fast, cheap, and effectively obsolete on their own.
Stateful inspection firewalls add the connection table described above. This is what most people mean by a firewall, and stateful inspection is still the core of every type below.
Application layer firewalls, sometimes called proxy firewalls, understand the protocol they carry. They can enforce that traffic on port 443 really is HTTPS rather than something tunneling through the port everyone leaves open.
Next generation firewalls are the current default. A stateful firewall plus application awareness, user identity from the directory, intrusion prevention, and reputation feeds. The useful part is not the feature list: it is that a rule can say finance may reach the accounting application, rather than that this address range may reach that port.
Web application firewalls are a different animal despite the name. A WAF sits in front of a web application and inspects the requests for attacks against that application, injection attempts and the rest. It does not replace a network firewall and a network firewall does not replace it.
Where it runsNetwork based, host based, cloud based
Firewalls get classified two ways at once, and mixing the two axes is where conversations go wrong. One axis is where the firewall runs. The other is how deep it looks.
Network based firewalls sit in the path between networks and filter the traffic of everything behind them. This is the appliance at the edge, or a filtering function on a router or a layer 3 switch. One device protects many machines, and it sees only the traffic that crosses it.
Host based firewalls run on each machine and filter that machine only. Every modern operating system ships one. They see traffic a network firewall never does, including a neighboring machine on the same segment, and they are the control that limits how far an attacker moves after landing somewhere.
Cloud based firewalls are the same logic delivered as a service, either as the security groups and network rules inside a cloud provider or as a filtering service traffic is routed through. In a cloud network there is no cable to put an appliance on, so the filtering is a property of the network itself.
Most estates run all three, and they are not alternatives. The network firewall decides what may enter. The host firewall decides what one machine accepts from another. The cloud rules do the same job for the parts of the estate that have no data center.
The depth axis, by layer
The second axis is how far up the stack the firewall reads, and it decides what the device is capable of noticing.
| Type | Reads up to | Can distinguish | Cannot |
|---|---|---|---|
| Packet filtering | Layer 4, addresses and ports | Which port a connection uses | Whether the traffic on it belongs there |
| Stateful inspection | Layer 4, with a connection table | A reply from an unsolicited connection | What the connection carries |
| Application layer | Layer 7, the protocol itself | Real HTTPS from something tunneling on 443 | Encrypted payloads, without terminating them |
| Next generation | Layer 7, plus identity | Which user and which application | The same encryption limit as everything else |
Everything above layer 4 depends on being able to read the traffic. Since most traffic is encrypted, application awareness is often working from the destination name and the shape of the connection rather than from its contents, which is more than nothing and less than the brochure implies.
Threat featuresThreat prevention, and what it is really worth
A next generation firewall is sold on more than filtering, and the extra features vary in how much they earn their keep.
Intrusion prevention compares network traffic against signatures of known threats and blocks the matches. It is genuinely useful against opportunistic scanning and mass exploitation, which is most of the threats that reach an edge. It is weak against anything targeted, and it only inspects what it can read.
Reputation feeds block connections to addresses and domains known to be hosting threats. Cheap, effective against commodity malware calling home, and it fails quietly when the destination is a compromised legitimate service, which is now common.
Application control enforces which applications may cross the firewall, by recognizing them rather than by trusting the port. This is the feature that makes rules readable, because a rule can name the accounting system instead of an address range.
User identity pulls group membership from the directory so access rules apply to people rather than to network addresses. It is what makes a firewall rule survive somebody moving desk.
Decryption is the one to think hardest about. Inspecting encrypted traffic means the firewall terminates the connection, reads it, and re-encrypts it, which requires a certificate trusted by every client and puts the plaintext of everything through one device.
Some traffic must be excluded by law or by policy, banking and health among it. Organizations that turn it on for everything usually turn most of it back off.
The honest summary: filtering and segmentation are what a firewall reliably delivers. The threat prevention features raise the floor against untargeted attacks and should not be mistaken for a reason to relax anywhere else.
What it stopsWhat a firewall actually stops
Stated as a threat model rather than a feature list, a network firewall earns its place against four things.
Unsolicited inbound connections. The background noise of the internet is constant scanning, and every network with a public address receives it within minutes of appearing. A deny by default rule set means that traffic reaches nothing. This is the largest single security win and it is invisible, because success looks like nothing happening.
Services that were never meant to face the internet. Databases, management interfaces, file shares and remote desktop are exposed by accident more often than by decision, usually by a rule added for a project and never removed. The firewall is where that is prevented and where it is discovered.
Lateral movement, if the network is segmented. An attacker who reaches one machine tries to reach the next. On a flat network nothing is in the way. With internal segmentation, the firewall between departments is a control point, and the access an intruder has bought themselves is limited to what those rules allow.
Outbound connections to known bad destinations. Malware that has landed needs to reach its operator. Blocking known destinations breaks a share of that, and the logs of the attempt are frequently the first sign anyone has that something is inside.
Against those four, a well configured firewall is the highest value network security control there is, and none of them requires reading a single byte of encrypted data.
What it does not touch is equally clear, and it follows.
What it missesWhat a firewall does not do
This is the part vendor pages hurry past, and it decides how much a firewall is worth.
It does not read encrypted traffic. Most network traffic is now encrypted, so a firewall sees where a connection is going and how much data is flowing, not what is in it.
Inspecting the content requires terminating the encryption on the firewall, which means installing a certificate on every client and accepting that the firewall now holds the plaintext of everything. That is a real deployment with real trade offs, not a checkbox.
It does not stop what you invited. A user who downloads and runs something has made an outbound connection the rules permit. That is not a firewall failure, it is the firewall doing exactly what it was told.
It does not see traffic that never crosses it. Two machines on the same network segment exchange packets directly. The firewall at the edge learns nothing about it, which is the argument for host firewalls and for segmentation.
It does not know a stolen credential from a real one. Someone logging in from an allowed address with a valid password looks exactly like the person they stole it from. That is what multi factor authentication is for.
It is not a backup, an antivirus, or a patch. It reduces what can be reached across the network.
It does nothing about what happens on a machine once something is running there, and nothing about data already copied out through a connection it allowed. That gap has a shape worth seeing whole, which is the difference between network security and cyber security.
ComplianceWhat auditors and insurers ask about
A firewall is one of the few security controls named directly in compliance regimes rather than implied, and what is asked for is rarely the device.
Documented rules with a business reason. The card industry standard asks for configuration standards and for each rule to have a documented purpose. An auditor reading a rule set full of uncommented entries is looking at a finding, regardless of whether the network is actually well protected.
A review on a schedule, with evidence it happened. Most regimes want the rule set reviewed at defined intervals. The review is not the hard part; producing evidence a year later that it happened is.
Segmentation between the sensitive systems and everything else. Where card data or health data lives, the network holding it is expected to be separated from the general one, and the boundary is expected to be enforced rather than assumed. This is the requirement that most often turns into real work, because it means changing a flat network.
Change control. Who asked for a rule, who approved it, when it went in. A firewall with no change record is a control nobody can prove the state of.
Logs, kept for a stated period. Both what was denied and what was changed, retained long enough to investigate something discovered months later.
Cyber insurers now ask a shorter version of the same list on the application form, alongside questions about multi factor authentication and backups. Answering yes to a firewall question while the rule set has not been reviewed since it was installed is the kind of answer that gets examined during a claim rather than during underwriting.
The useful reframe: the security value of a firewall comes from the rules, and the compliance value comes from being able to show why each one exists. Both point at the same discipline, which is why the maintenance advice below is not administrative overhead.
MaintenanceRules that stay maintainable
Firewall rule sets rot. They rot in a specific way, and the countermeasures are cheap if applied from the start.
Deny by default, always. The last rule in the set denies all traffic. Anything permitted sits above it, deliberately, at the level of specificity the business actually needs.
Comment every rule with why and who. A rule with no explanation is a rule nobody dares remove, and rule sets grow because of it. Ticket number, requester, date.
Use groups, not addresses. A rule that names a group is a rule you edit once when the membership changes, and it survives a network renumbering. A rule set full of literal addresses becomes untouchable within a year.
Review on a schedule. Most firewalls can report which rules have matched nothing. A rule that has not fired in a year is either dead or protecting something nobody uses, and both are worth knowing.
Log the denies, and read them. Denied packets are the interesting ones. It is either something legitimate that needs a rule, or something that should not have been trying, and both are worth a look.
Watch the temporary rule. Every rule set has one, added to test something, placed near the top so it works immediately, and never removed. It is usually the widest rule in the file.
ComparisonWhere a firewall sits, and what each placement protects
| Placement | What it protects | Typical form |
|---|---|---|
| At the internet edge | Everything behind it, from unsolicited inbound traffic | An appliance or a router feature |
| Between internal segments | One department or system from another | The same appliance, or a layer 3 switch |
| On each machine | That machine, including from its neighbors | Built into the operating system |
| In front of an application | The application, from attacks aimed at it | A WAF, often hosted |
| In a cloud network | Traffic between and into cloud subnets | Security groups and network rules |
The two worth insisting on are the first and the third. An edge firewall is table stakes. The host firewall on every machine is the one most organizations leave at defaults, and it is what limits the damage once something is already inside, because an attacker who lands on one laptop then finds the rest of the network is not open to them.
Segmentation between internal networks is the middle ground, and it is where the real security gain sits for most companies. A flat network means one compromised machine has access to everything. Splitting it means the firewall gets a say in what any machine can reach.
FAQFrequently asked questions
What is a firewall in simple terms?
A network security control that sits between two networks and decides which traffic is allowed across, using a list of rules.
Is a firewall hardware or software?
Both exist. Network based appliances at the edge, host based software built into every operating system, and cloud based services doing the same job. The filtering logic is identical.
What does stateful mean?
The firewall remembers the connections it has allowed, so replies to those connections pass without needing their own rule. A stateless firewall checks each packet in isolation and cannot do that.
What is the difference between drop and reject?
Drop discards silently and the sender waits for a timeout. Reject sends back a refusal so the sender fails immediately. Drop facing the internet, reject internally where the sender is a colleague.
Does a firewall stop viruses?
Not directly. It can block connections to destinations known to host threats, and a next generation firewall can inspect unencrypted traffic, but most malware arrives over a connection the user made and the rules allowed.
Do I still need a firewall if everything is encrypted?
Yes. Encryption protects the content of a connection. A firewall decides whether the connection is permitted at all, which is a separate question.
What does Cisco ASA stand for?
Adaptive Security Appliance. The Cisco ASA 5500 Series Adaptive Security Appliances, or simply Cisco ASA, is Cisco's line of network security devices, introduced in 2005 to succeed the Cisco PIX firewall.
It is a unified threat management device that combines several network security functions, firewall, VPN and more, in one appliance, which is why it is one of the most widely used firewall and VPN products in smaller networks.
What is a next generation firewall?
A stateful firewall that also understands applications and users, so a rule can name a group of people and an application rather than an address range and a port.
Is a WAF the same thing?
No. A web application firewall inspects requests aimed at one web application. A network firewall decides what may cross between networks. They protect different things.
Should the Windows firewall be left on?
Yes. The host firewall is what limits movement once something is already inside the network, and it is the control most often left at defaults.
Why does the rule order matter so much?
Because the first matching rule decides and nothing below it is read. A broad allow placed above a specific deny makes the deny dead, with no warning.
What is a five tuple?
Source address, destination address, source port, destination port and protocol. The five fields a classic firewall rule matches on.
How often should rules be reviewed?
At least yearly, and after any project that added a batch of them. Ask the firewall which rules have matched nothing, and start there.
What is the ASA full form?
ASA stands for Adaptive Security Appliance. It is Cisco's long running firewall line, which replaced the PIX. Cisco now sells the Secure Firewall range running Firepower Threat Defense software, and many ASA units remain in service.
Keep readingRelated concepts
Read next · Remote access VPN vs Proxy A secure web gateway is a proxy doing the outbound half of this job. Open this next13 min- Identity and access · 16 min What Is MFA? A firewall cannot tell a stolen password from a real one. This is what does.
- Directory and identity · 15 min Active Directory Explained Firewall rules that name people rather than addresses are reading them from the directory.
- Identity and access · 13 min Zero Trust Explained Zero trust says the perimeter is not sufficient, not that a firewall is useless.
- Routing · 12 min What Is BGP? What sits between a network and the internet once the routing has decided where traffic goes.
- Operations · 14 min What a Webhook Is, and the Four Things That Break One What has to be opened, and how narrowly.
- Remote access · 14 min WireGuard Explained What still has to filter the traffic once it comes out of the tunnel.
- Network security · 12 min IDS vs IPS What inspects the content of the traffic a firewall has already allowed through.
- Ports · 12 min What Is a Port Number? What the rules on a firewall are actually naming.
- Managed IT · 11 min What an MSSP Sells, and What Round the Clock Really Costs A device whose logs belong in the monitoring scope.
- Network security · 14 min What Is a WAF? What inspects the content of the web traffic this firewall has already allowed.
- Protocols · 11 min What Is ICMP? What the rules blocking or permitting this protocol actually look like.
- Switching · 14 min What Is a VLAN? The control that turns separation into something that actually blocks traffic.
- Network security · 9 min Cyber Security vs Network Security, and What the Firewall Does Not Cover The wider coverage map this control is one row of, and which rows have nothing on them.
- Network security · 9 min The Implicit Deny, and Why the Rule You Just Added Did Nothing The rule at the end of every list it evaluates.
- Ports · 10 min SMB Port 445, and the One Rule That Matters About It Where the rules about this port are actually written.
- Remote access · 11 min NAT Traversal, and Why One Way Audio Is Always the Same Bug What the traversal is working around in the first place.
- Network security · 10 min Stateful vs Stateless Firewall, and Where Stateless Filtering Still Lives How stateful and stateless filtering differ, and where stateless rules still run on your network.
- Network security · 10 min DoS vs DDoS, and What a Small Business Can Actually Do About Either One source attacks against distributed floods, and why a flood fills the line before the firewall.
- Ports · 10 min TACACS+ vs RADIUS, Port by Port and Claim by Claim The AAA protocols behind the login prompt on a firewall or switch.