{"id":20451,"date":"2020-01-29T22:23:06","date_gmt":"2020-01-29T22:23:06","guid":{"rendered":"https:\/\/www.arimetrics.com\/glosario-digital\/firewall"},"modified":"2026-09-27T15:15:50","modified_gmt":"2026-09-27T15:15:50","slug":"firewall","status":"publish","type":"encyclopedia","link":"https:\/\/www.arimetrics.com\/en\/digital-glossary\/firewall","title":{"rendered":"Firewall"},"content":{"rendered":"<p><img decoding=\"async\" class=\"boxpad alignright wp-image-14310 size-full\" src=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2020\/01\/Firewall-1.png\" alt=\"Firewall\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2020\/01\/Firewall-1.png 300w, https:\/\/www.arimetrics.com\/wp-content\/uploads\/2020\/01\/Firewall-1-150x150.png 150w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><strong>Definition:<\/strong><\/p>\n<p>A <strong>firewall<\/strong> is a security system that controls traffic between networks or devices with different levels of trust. It examines communications and applies a rule-based policy to allow, block or log them.<\/p>\n<p><strong>It can be implemented<\/strong> as <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/software\">software<\/a>, as a <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/hardware\">hardware<\/a> device or as a virtual service in cloud infrastructure. Its location and configuration determine which connections it can monitor: a network firewall protects a boundary or segment, whereas a host firewall acts on the device where it is installed.<\/p>\n<p>A firewall provides a <strong>layer of access control<\/strong>, but it does not establish by itself that all permitted traffic is legitimate or replace other security measures. Its effectiveness depends on communications passing through the protected point and on rules that reflect the actual risks of the environment.<\/p>\n\n<h2>How a firewall works<\/h2>\n<p>When a communication reaches the firewall, the system <strong>compares its data with a previously configured policy<\/strong>. The decision can be based on several attributes of the connection:<\/p>\n<ul>\n<li><strong>Source and destination:<\/strong> IP addresses, networks or zones between which traffic moves.<\/li>\n<li><strong>Protocol and port:<\/strong> For example, TCP, UDP, HTTPS or ports associated with a service.<\/li>\n<li><strong>Direction:<\/strong> Inbound, outbound or internal traffic between segments.<\/li>\n<li><strong>Connection state:<\/strong> The relationship between a packet and a session that has already been initiated and authorized.<\/li>\n<li><strong>Application or identity:<\/strong> Some products recognize programs, services or users to apply more specific controls.<\/li>\n<\/ul>\n<p>A rule can accept traffic, silently drop it, reject it explicitly or generate a log entry. The policy usually orders rules by priority and ends with a default action for anything that does not match the preceding conditions.<\/p>\n<p>Event logs help investigate connections and refine policy, although <strong>logging does not amount to detecting every attack<\/strong>. Visibility depends on the available functions, encryption and the configured level of inspection.<\/p>\n<h2>Types of firewall<\/h2>\n<p>Firewalls can be classified by how they inspect traffic. These techniques are not always mutually exclusive, as one solution may combine several of them.<\/p>\n<p><strong>Packet filtering<\/strong> compares headers and network fields with rules for addresses, protocols and ports. It is a basic and fast control, but it has less context about the communication.<\/p>\n<p><strong>Stateful inspection<\/strong> maintains information about active connections and evaluates whether each packet belongs to a valid session. This provides a better distinction between expected responses and unsolicited connection attempts.<\/p>\n<p><strong>Proxies and application firewalls<\/strong> intermediate connections and can interpret specific protocols. A next-generation firewall, or NGFW, adds functions such as application identification, intrusion prevention or integration with threat intelligence, depending on the product and its configuration.<\/p>\n<h2>Deployment models<\/h2>\n<p>Location defines the scope of control. An architecture may use several firewalls together to protect different boundaries and segment resources.<\/p>\n<ul>\n<li><strong>Network firewall:<\/strong> It sits between networks, subnets or security zones and controls traffic that crosses that point.<\/li>\n<li><strong>Host firewall:<\/strong> It runs on a computer or server and applies rules to that system&#8217;s own communications.<\/li>\n<li><strong>Virtual or cloud firewall:<\/strong> It protects networks, workloads and services through software-defined controls within virtual infrastructure.<\/li>\n<\/ul>\n<p>Segmentation can restrict movement between internal areas. For example, an organization can separate user devices, servers and administration systems and permit only the necessary connections between them.<\/p>\n<h2>Differences from other security controls<\/h2>\n<p>A firewall controls network communications. Antivirus or endpoint protection analyzes files, processes and system behavior to identify <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/malware\">malware<\/a> and other harmful activity. The controls address different risks and can work together.<\/p>\n<p>An IDS observes events and raises alerts for suspicious patterns, while an IPS can intervene to block them. Some NGFWs include intrusion prevention capabilities, but <strong>a firewall and an IDS\/IPS are not synonyms<\/strong>.<\/p>\n<p>A WAF specializes in HTTP and HTTPS traffic directed at web applications. It analyzes application-layer requests, whereas a general network firewall controls a broader range of protocols and connections.<\/p>\n<h2>The firewall&#8217;s role in cybersecurity<\/h2>\n<p>Firewalls help reduce the exposed attack surface, separate environments and apply least privilege to communications. They also provide logs for monitoring and can contribute to controls required by a security policy or framework.<\/p>\n<p>Their limitations matter. Firewalls alone do not prevent phishing, the use of stolen credentials, application vulnerabilities or harm carried through an authorized connection. Encrypted traffic also hides its content unless a compatible inspection function is present and properly configured.<\/p>\n<p>An effective policy requires <strong>justified and reviewed rules<\/strong>, removal of unnecessary permissions, system updates and log analysis. The firewall is one part of a broader strategy that includes segmentation, identity management, endpoint protection, backups and vulnerability remediation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A firewall controls network traffic through rules. Learn how it works, its main types, deployment models, differences and security limitations.<\/p>\n","protected":false},"author":6,"featured_media":80777,"template":"","encyclopedia-tag":[1405,1263],"class_list":["post-20451","encyclopedia","type-encyclopedia","status-publish","has-post-thumbnail","hentry","encyclopedia-tag-network-access","encyclopedia-tag-web-encryption"],"_links":{"self":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia\/20451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia"}],"about":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/types\/encyclopedia"}],"author":[{"embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/users\/6"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/media\/80777"}],"wp:attachment":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/media?parent=20451"}],"wp:term":[{"taxonomy":"encyclopedia-tag","embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia-tag?post=20451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}