A firewall is a network security device that monitors and filters incoming and outgoing traffic based on predefined security rules to protect against unauthorized access.
A firewall is a security device or software that monitors network traffic and enforces access control policies by allowing or blocking packets based on predefined rules. Firewalls form the first line of defense at network boundaries, segmenting trusted and untrusted zones. They range from simple packet filters to sophisticated next-generation firewalls with deep packet inspection.
Key types include packet filtering firewalls that inspect headers, stateful inspection firewalls that track connection state, proxy firewalls that intermediate application traffic, and next-generation firewalls that add application awareness and intrusion prevention. Web application firewalls protect HTTP traffic specifically. Cloud firewalls provide virtual network security in cloud environments.
Next-generation firewalls combine traditional packet filtering with application-layer inspection, integrated intrusion prevention, SSL/TLS decryption, user identity awareness, and threat intelligence feeds. They can identify and control applications regardless of port or protocol, enabling granular policies that traditional firewalls cannot enforce based on IP addresses and ports alone.
Testers perform firewall rule audits, attempt to bypass access controls using protocol tunneling and fragmentation, test for overly permissive rules, and identify misconfigurations that allow unauthorized access. They verify egress filtering, check for default credentials on management interfaces, and assess whether the firewall properly blocks lateral movement between network segments.
A web application firewall operates at the application layer to protect web applications from attacks like SQL injection, cross-site scripting, and request forgery. WAFs analyze HTTP requests against rulesets and behavioral models, blocking malicious payloads before they reach the application. They complement network firewalls rather than replacing them as part of a defense-in-depth strategy.
Common misconfigurations include overly broad allow rules, failure to implement egress filtering, exposed management interfaces, disabled logging, outdated firmware, default credentials, and permitting unnecessary protocols. Shadow rules that are never matched and stale rules for decommissioned systems also create risk by obscuring the effective security policy.
In zero trust architectures, firewalls enforce microsegmentation policies that restrict lateral movement between workloads. Rather than trusting all traffic inside the network perimeter, micro-segmentation firewalls apply least-privilege access between every communication pair. This approach limits blast radius and prevents attackers from freely moving through the environment after initial compromise.
Yes. Host-based firewalls provide an additional defense layer directly on endpoints, protecting against threats that originate within the network or bypass perimeter controls. They enforce application-specific policies and protect mobile devices operating outside the corporate network. The combination of network and host-based firewalls implements true defense-in-depth at both layers.