Question

What does a firewall actually do?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A firewall decides which network traffic is allowed through based on rules. The important distinction is direction, because inbound and outbound filtering solve completely different problems and people usually mean only the first.

Inbound filtering blocks unsolicited connections from outside. This is the protection most people picture, and on a home network your router provides it implicitly through address translation: since internal devices have private addresses, there is no route for an outside connection to reach them unless you deliberately forward a port. This is why home devices are not directly exposed even without a configured firewall.

Outbound filtering restricts what your own machines may connect to. It matters mainly in corporate environments, where it limits what compromised software can do, and it is why some workplaces block particular services.

Operating systems also include their own firewall, which matters most on networks you do not control. On a public wireless network you are sharing a segment with strangers, and the router protection between you and them does not exist. A machine configured to trust the local network will share files and services with everyone on that network, which is exactly why systems prompt you to classify a network as public or private on first connection. That prompt is a security decision, not a formality.

What a firewall does not do is inspect the content of allowed traffic for malicious material, distinguish legitimate from malicious use of a permitted service, or protect against anything you invited in yourself by clicking a link or running a download.

It is one layer among several, and its particular strength is reducing the surface an attacker can reach at all.

Related Questions