Firewall

A device or software that enforces a policy on traffic passing between networks or into a host, permitting or blocking it by rules based on addresses, ports, state or content.

A firewall enforces a security policy at a point where traffic crosses, allowing or denying each flow according to rules. NIST SP 800-41 Rev 1 gives guidance on firewall types and policy. A packet filtering firewall checks header fields such as addresses and ports. A stateful inspection firewall also tracks connections, so it can allow replies to traffic it has already permitted. An application-level gateway understands the application protocol and can act as a proxy, while a circuit-level gateway validates the session without reading its content. A next-generation firewall adds application awareness and intrusion prevention, and a web application firewall protects web applications specifically.

Firewalls can be network-based or host-based. A sound rule set commonly ends in a default deny. Their limits matter as much as their features: a firewall sees only traffic that passes through it, so one placed at the boundary does not inspect traffic between hosts inside the same segment, and it cannot judge encrypted content it does not decrypt. That is why segmentation, distributed firewalls and endpoint controls supplement it.

Exam relevance: questions in this area tend to turn on matching the firewall type to the depth of inspection a scenario needs. Candidates are also expected to recognise a default-deny rule set as the secure baseline.