A firewall monitors network traffic and can block suspicious connections according to security rules.
Firewalls enforce a boundary between networks or between a device and its network. Rules may examine addresses, ports, protocols, connection states, applications, or other characteristics. Depending on its design, a firewall can allow trusted traffic, reject unwanted traffic, or log activity for investigation.
Early firewalls primarily filtered packets and connections. Modern firewalls may inspect application behavior, integrate intrusion-prevention features, or run directly on individual computers as host-based firewalls. Network firewalls can be physical appliances, virtual services, or cloud-managed controls.
A firewall is not a complete security solution. It cannot reliably stop every malicious file, stolen credential, or authorized user acting improperly. Effective protection also depends on patching, authentication, monitoring, backups, and secure system configuration.