What is a firewall and how does it work?
Every computer guide says to keep your firewall turned on. But what is a firewall, and what is it actually doing? A firewall is a gatekeeper for network traffic. It sits between your computer or home network and the internet, checks what tries to pass, and lets through only what its rules allow.
This guide explains how a firewall works, the two main kinds, and the important thing it cannot do, using the glossary of the US National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency's (CISA) guide for homes and small offices. It ends with the free browser game Tank City Reboot, whose first stage is named FIREWALL.
What is a firewall? The definitions
NIST's glossary collects several definitions of a firewall from different documents. The simplest is a gateway that limits access between networks according to a security policy, a set of rules. Another calls it a device or program that controls the flow of network traffic between networks or computers with different security needs.
NIST also explains the name. A firewall sits at the meeting point of two networks, usually a private one, like your home, and a public one, like the internet. The term comes from fire doors, and from the firewall in a car that separates the engine from the passengers: a barrier that stops damage in one area from spreading to the next.
How a firewall decides what gets through
A firewall looks at each piece of traffic and compares it with its rules. CISA's guide to understanding firewalls explains that firewalls can be set to block data from certain addresses, certain applications or certain ports, while letting relevant and necessary data through.
- Addresses are where traffic comes from or goes to. A rule can block addresses known to be malicious.
- Applications are the programs sending or receiving the traffic. A rule can stop one program from using the network at all.
- Ports are numbered entry points on a computer, each usually tied to one kind of service. A rule can close ports that nothing should be using.
One NIST definition captures the usual default: block unauthorized access coming in, while permitting outward communication. In practice that means the web pages you ask for come back to you, while connection attempts nobody asked for are turned away.

Hardware and software firewalls
CISA describes two kinds, and most homes already have both.
- Hardware firewalls, often called network firewalls, are physical devices placed between your computer and the internet. Many home and small office routers include firewall features. Their strength is protecting every device on the network at once, as an extra line of defense before attacks reach any computer.
- Software firewalls run on the computer itself. CISA notes that most operating systems include one, and that you should turn it on even if you have a hardware firewall too. A software firewall can control what each program on the computer does on the network. Its weak point is that it sits on the same system it protects.
CISA's summary is reassuring: the decision to use a firewall matters more than which type you choose.
What a firewall cannot do
This is the part people most often get wrong. CISA says it plainly: do not be lulled into a false sense of security. Firewalls mainly protect against malicious traffic, not malicious programs, and may not protect you if you install or run malware yourself.
CISA flags one more weak point. Firewalls come preconfigured, and the default settings are typically less restrictive, which can leave gaps. It is worth reading what your firewall's settings actually allow. And a firewall works best alongside other measures, such as antivirus software and safe habits.
A worked example: one household, two firewalls
Picture a household with a home router and a laptop. Here is what each firewall does through a normal week, and where both fall short.
- At home. Someone on the internet tries to connect to the laptop directly. Nobody inside asked for that connection, so the router's firewall drops it before it reaches any device.
- Browsing. The laptop requests a web page. The request goes out, the page comes back, and both firewalls let it through, because it is traffic the laptop asked for.
- At a cafe. The laptop joins public wifi, away from the home router. Now only the laptop's built-in firewall stands between it and everyone else on that network, which is why CISA says to keep it on even when you have a router firewall at home.
- The download. Back home, someone downloads a "free" program from a link and runs it. It is a trojan. Both firewalls see only a download the user asked for, so neither stops it.
Steps 1 to 3 show a firewall doing its job well. Step 4 shows its limit. Keeping out unwanted traffic is not the same as stopping a harmful program you let in yourself. Our guide to the types of malware explains why trojans get past exactly this kind of defense.
Learn the idea by playing: Tank City Reboot
Tank City Reboot is a tank game set inside a computer: your antivirus tank guards the CPU core on a circuit board, and every stage, enemy and wall is named for a real computing idea. The first stage is FIREWALL, and it opens with this fact: "A firewall checks network traffic against rules and blocks what breaks them."
Firewall is also the main wall on the map. It breaks under fire a block at a time, and its card adds, "Firewalls sit between networks and filter what passes." The CPU core sits inside its own ring of firewall, and a Firewall rebuild power-up turns that ring to silicon, which stops shots, for fifteen seconds.

In the second game, Tank City Zero Day, the Ransomware tank's shots lock firewall into silicon. A game teaches the word and one idea, and it is not a security course or a substitute for a real firewall. Our guide to zero-day flaws is a good next read.
Frequently asked questions
What is a firewall in simple words?
A gatekeeper for network traffic. It sits between your computer or network and the internet and blocks traffic its rules do not allow.
Do I need a firewall if my router has one?
CISA says yes: turn on the firewall built into your operating system even if you have a hardware firewall, which matters most when your device leaves home.
Does a firewall stop viruses?
Not on its own. CISA notes that firewalls mainly protect against malicious traffic, not malicious programs, and may not help if you run malware yourself.
Why is it called a firewall?
NIST explains that the name comes from fire doors and the firewalls in cars: barriers that stop damage in one area from spreading to another.
Get started
Play Tank City Reboot: it is free, plays in your browser on a computer or a phone, and needs no account. Start with the FIREWALL stage and learn how fast the walls fall under fire.
Comments
No comments yet.
Sign in or make an account to comment.