What is a firewall and what does it actually do?¶
A firewall is a traffic-control function. It compares network traffic with rules and decides whether to allow, block, record or alert on it.
Where it may exist¶
A firewall may be part of a home router, laptop, server, cloud service or corporate network. It does not have to be a separate box.
Rules may consider direction, addresses, ports, protocol, connection state, application or identity.
A simple example¶
A laptop starts a web connection. The firewall allows the outgoing traffic and may allow the replies because they belong to the same connection. An unrelated inbound attempt may be blocked because no rule permits it.
This is like a gatekeeper checking passes against a rulebook. The gatekeeper controls the gate; it does not know everything that happens after the person enters.
What the decision means¶
“Allowed” means the traffic passed that firewall’s control. “Blocked” means it did not pass there. Neither word alone proves that the connection completed, that the activity was safe or that a person was responsible.
The firewall may see private addresses, public addresses or translated values depending on its position. Its logs must be interpreted in that context.
The point to remember
A firewall is a rule-based observation and control point. What its record proves depends on where it sits, what it was configured to record and which event it actually captured.