Firewall (network firewall)
A firewall (network firewall or edge firewall) is a means of network traffic control that filters data packets based on specified rules, protecting the network from unauthorized access, malware and network attacks.
What is a firewall in simple words
A firewall (also called an edge firewall or border firewall) is a barrier between your internal network and the outside world, such as the Internet. Imagine it as a checkpoint: it checks all data trying to enter or leave the network and lets through only what complies with security rules.
When you open a website, send an email or connect to a corporate network, the firewall analyzes each data packet. It looks at where the packet came from, where it is heading and what it contains. If the packet looks suspicious or violates the rules, the firewall blocks it. This is the first and most important line of defense of any computer network, be it home Wi-Fi or the infrastructure of a large corporation.
Without a firewall, your network becomes vulnerable to many threats: hackers can scan your ports and try to break into the system, malware can independently connect to command-and-control servers to receive instructions, and attackers can intercept transmitted data. The firewall prevents all these scenarios by creating a reliable barrier between your network and the outside world.
Modern firewalls are not just packet filters. They analyze traffic at various layers of the OSI model, providing multi-level protection. They can recognize application types, block access to dangerous sites, prevent confidential data leakage and even detect anomalies in user behavior. Read more about how firewalls integrate into a comprehensive protection system in the article SIEM system.
It is important to understand that a firewall is not only protection against external threats. It also controls internal traffic, preventing the spread of malware inside the network and limiting employee access to unwanted resources. For example, a firewall can block access to social networks during working hours or prohibit the transmission of confidential data outside the company.
Types of firewalls
There are several types of firewalls, each with its own features and scope of application:
- Packet filters: Analyze only IP packet headers. This is the simplest and fastest type, but not flexible enough. They check the IP addresses of the sender and recipient, ports and protocols. Packet filters are suitable for small networks with low security requirements. However, they do not analyze packet contents and therefore cannot detect application-level attacks.
- Stateful Inspection: Analyze not only individual packets but also the state of connections, which allows more accurate detection of attacks. They remember which connections were established and check whether incoming packets match existing sessions. This significantly increases the level of protection compared to simple packet filtering, since it blocks packets that are not part of established connections.
- Proxy firewalls (application-level gateways): Operate at the application layer of OSI, analyzing the content of traffic (for example, web requests), which provides the highest level of control but reduces performance. They can check the content of web pages, detect SQL injection and other application-level attacks. Proxy firewalls can also cache frequently requested content, which speeds up access to resources.
- NGFW (Next-Generation Firewalls): Combine the functions of a packet filter, IPS (intrusion prevention system), application control and antivirus scanning. This is the modern standard for corporate networks. NGFWs can identify applications regardless of ports and protocols, which allows creating more accurate security rules. Read more about NGFW in the article NGFW.
Each type of firewall has its own strengths and weaknesses, and the choice of a suitable solution depends on the specific business tasks. For small organizations, a simple packet filter or a stateful solution may be enough. For medium and large companies, especially those operating in regulated industries, it is recommended to use NGFW with extended security features.
It is also worth noting that firewalls can be implemented as software (installed on a server or workstation), a hardware device (a specialized network appliance) or a cloud service (FWaaS — Firewall as a Service). Cloud firewalls are becoming increasingly popular because they do not require the purchase and maintenance of expensive equipment and scale easily.
Software firewalls are installed on end devices, protecting individual network nodes. This is especially important for mobile employees who connect to the corporate network from different places. Hardware firewalls are installed at the network boundary and protect the entire organization as a whole.
Logging and monitoring
Firewalls generate logs of all events that integrate with SIEM systems and monitoring centers (SOC). This allows information security analysts to see the threat picture in real time. Every blocked connection, every intrusion attempt and every suspicious packet is recorded and can be analyzed to identify patterns and prevent future attacks.
Firewall logs contain a huge amount of information: event time, source and destination IP addresses, ports and protocols used, action (allowed/blocked), and often the reason for blocking. Without a centralized system for collecting and analyzing logs (SIEM), it is almost impossible to process such a volume of data manually.
For critical information infrastructure (CII) facilities, keeping firewall event logs is a mandatory regulatory requirement. Logs must be stored for at least a year and be available for audits. SIEM systems automate this process, ensuring compliance with regulatory requirements.
The installation service includes the installation and configuration of firewalls of any type. This is a complex process that requires high qualifications and experience, since a misconfigured firewall can either fail to protect the network properly or block legitimate traffic, disrupting business operations.
When configuring a firewall, it is important to follow the principle of least privilege: allow only the traffic that is truly necessary for operation and block everything else. Regular audit of firewall rules helps identify outdated or redundant rules that can become a source of vulnerabilities. Read more about the approaches in the technologies section.
Frequently asked questions
What is a firewall in simple words?
A firewall is a virtual checkpoint that filters incoming and outgoing traffic, letting only safe data through and blocking threats. It works like a security guard: checks data packets, verifies them against the rules and decides whether to allow or block. Integration with SIEM and SOC provides comprehensive protection. The installation service will help you deploy a firewall in your network.
What is a firewall?
A firewall is a computer network security system that restricts the passage of incoming, outgoing and intra-network traffic. It is a software or hardware-software tool that decides whether to allow or block a data packet. Modern firewalls integrate with SIEM and NGFW for deep traffic analysis. The installation service will help you configure a firewall.
Where is a firewall installed?
A firewall is installed at the boundary between the organization's internal network and external networks (usually the Internet). It can also be placed inside the corporate network in front of segments with confidential data. Firewalls can be hardware (installed in server racks) and software (on servers and workstations). The installation service will help you correctly place and configure a firewall in your infrastructure.
How does a firewall differ from a router?
A router forwards data between networks, directing packets in the right direction, but does not analyze their contents. A firewall filters traffic and prevents attacks, making decisions based on security rules. Modern firewalls integrate with NGFW and SIEM. The installation service will help you choose and configure the right solution.
What is another name for a firewall?
A firewall is also called an edge firewall, security firewall or network firewall. All these terms denote the same protection tool — a network traffic filtering system. Modern solutions include NGFW (next-generation firewalls) with extended functions. The installation service will help you deploy a firewall in your organization.
What are some examples of firewalls?
Examples of firewalls: hardware — Cisco ASA, FortiGate, Check Point; software — UserGate, pfSense, OPNSense; built-in — Windows Firewall, iptables in Linux. Modern NGFW solutions combine filtering with IPS, antivirus and application control. The installation service will help you choose and configure the optimal solution for your network.
What does a firewall protect against?
A firewall protects a computer network from unauthorized access, port scanning, network attacks and malware. It controls network traffic, blocks suspicious connections and prevents data leaks. Integration with SIEM and SOC provides comprehensive security monitoring. The installation service will help you properly configure protection. To study related concepts, we also recommend reading about Captcha, DDoS attack, Unauthorized access and Sandbox.
Other terms in «Information Security»
Was this information helpful?
Protect your network today
Leave a request — our information security specialists will help you select, configure and integrate firewall (network firewall) into your infrastructure. We will protect your data from threats.