Skip to content
lesson Networks and business IT Beginner 3 min read

What is a firewall?

A firewall decides which network traffic may pass and which is blocked. The two kinds, what a firewall cannot stop, and what to check on yours.

A firewall is a device or program that controls which network traffic may pass between two networks, or in and out of a single computer. In an office it usually sits between your network and the internet, checks each connection against a list of rules, and either lets it through or blocks it.

How it decides

The rules are written by whoever sets the firewall up. A rule can refer to where the traffic comes from or is going (a network address), which application is sending it, or which port it uses. A port is a numbered channel that a particular kind of service listens on.

The Australian Signals Directorate recommends setting firewalls to deny by default. Anything that no rule specifically allows is blocked, so traffic nobody planned for does not get through.

The two kinds

  • A network firewall is a physical device between your computers and the internet. It protects everything behind it at once. Many small office routers include firewall features, so you may already have one.
  • A software firewall runs on an individual computer. Most operating systems have one built in. It can control what each application on that computer is allowed to do on the network.

CISA’s advice is to turn on the built-in software firewall even when a network firewall is in place. The network firewall cannot see what happens between two computers inside the office, and a laptop that leaves the building leaves the network firewall behind.

What a firewall does not do

A firewall filters traffic. It does not judge what people do with the traffic it allows. If a staff member opens an attachment or installs a program that turns out to be malicious, the firewall may not help, because the connection that brought it in was one it was told to permit. That is why spotting a phishing email and keeping software patched still matter.

The Australian Signals Directorate makes the same point about network design: a firewall on its own is not enough as the only security measure.

What to check on yours

  • The settings. Most firewalls arrive preconfigured, and CISA notes the default configuration is typically the less restrictive one. Somebody should have reviewed it for your office.
  • Updates. A firewall faces the internet all day, and attackers look for unpatched ones. Security updates need to go on promptly.
  • Who can log in. Limit the administrator account to the people who need it and protect it with multi-factor authentication.
  • What is switched on. Turn off services and remote connections nobody uses.
  • The logs. Someone should look at them, or be alerted by them, so that unusual activity is noticed.

If you cannot say who looks after the firewall or when it was last updated, start there. Our firewall and network security service covers setup, updates and monitoring, and A cyber security checklist for small business puts the firewall in context with the other basics.

Sources

  1. SP 800-41 Rev. 1: Guidelines on firewalls and firewall policy (NIST) csrc.nist.gov
  2. Firewall: glossary (NIST) csrc.nist.gov
  3. Understanding firewalls for home and small office use (CISA) cisa.gov
  4. Security considerations for edge devices (Australian Signals Directorate) cyber.gov.au
  5. Implementing network segmentation and segregation (Australian Signals Directorate) cyber.gov.au

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.