How Does a Firewall Work? (Beginner Explainer)
A firewall is a filter that decides which network traffic may enter or leave a device or network. It matches packets against allow/deny rules (ports, IPs, directions). Host firewalls protect one machine; network firewalls sit on the path for many devices. Firewalls reduce exposure — they do not replace updates, MFA or careful browsing.
Friends! At home a Jio router, on the laptop Windows Firewall, on EC2 a security group — all are firewall concepts. Today in beginner language: inbound vs outbound, host vs network, rules, and the firewall's limit. No bypass recipes — understand defence.
मित्रांनो! घरी Jio router आहे, laptop वर Windows Firewall, EC2 वर security group – सगळे firewall concepts आहेत. आज beginner language मध्ये: inbound vs outbound, host vs network, rules, आणि firewall ची limit. Bypass recipes नाही – defence समजून घेऊया.
मित्रों! घर पर Jio router है, laptop पर Windows Firewall, EC2 पर security group – सब firewall concepts हैं. आज beginner language में: inbound vs outbound, host vs network, rules, और firewall की limit. Bypass recipes नहीं – defence समझें.
Quick answer
Remember this vertical checklist:
- A firewall compares traffic to rules, then allows or blocks.
- Inbound = traffic coming toward you; outbound = traffic leaving your device/network.
- Default-deny inbound (only open what you need) is the safe habit.
- Host firewall = one laptop/server; network firewall / router = many devices.
- Cloud “security groups” are firewall-like allow lists for instances.
- Firewalls do not stop phishing clicks, stolen passwords or malware that already runs as you.
- Order matters: allow remote admin (SSH/RDP) before you tighten rules, or you lock yourself out.
Everyday map:
Phone / laptop OS firewall → host firewall
Home router / Jio gateway → network edge filter
AWS security group → cloud allow-list for one instance
Company perimeter firewall → shared network control
What do I need before this guide?
- Curiosity about why some ports are “open” and others are not.
- Optional lab: a Linux VM you own (see Harden a Linux server checklist).
- Optional: home router admin page (login only on your network — never share the password).
How does a firewall work (simple flow)?
Internet traffic hits a firewall. Allowed ports pass through; unexpected inbound traffic is blocked by the rules.
Internet traffic firewall ला भेटतो. Allowed ports जातात; unexpected inbound traffic rules ने block होतो.
Internet traffic firewall से टकराता है. Allowed ports गुज़रते हैं; unexpected inbound traffic rules से block होता है.
Read the flow as a vertical list:
- A packet arrives (or wants to leave).
- The firewall reads simple facts: source, destination, port, protocol, direction.
- It checks rules from top to bottom (or by priority).
- First matching action wins: allow or deny (exact products differ).
- Allowed traffic continues; denied traffic is dropped or rejected.
- Many firewalls are stateful: they remember a short conversation so return traffic for an allowed session can pass without a separate messy rule.
Your job as a beginner defender: few inbound allows, clear purpose for each open port, and logs when something unexpected hits the wall.
Real incident (public lesson) — exposed remote desktop without a tight firewall
WannaCry (2017) and NotPetya (2017) spread partly because many organisations had Wide-open remote services and weak internal segmentation. Public reporting also repeatedly shows RDP / remote admin left reachable from the whole internet with weak passwords — scanners find them in minutes.
Care-take bullets (defence only):
- Do not publish RDP/SSH to
0.0.0.0/0if you can avoid it. - Prefer VPN + MFA, bastion, or cloud “My IP” rules for admin ports.
- Patch border devices and OS quickly.
- Segment lab PCs from work-critical systems when you can.
- A firewall rule that never existed cannot block what was never filtered — write the allow list on purpose.
Red Team vs Blue Team (high level)
| Side | Goal (concepts only) | What they care about |
|---|---|---|
| Red Team | Reach a service that should not be public; move laterally if one host falls | Open ports, weak admin exposure, flat networks |
| Blue Team | Shrink what is reachable; detect noisy scans; keep admin paths MFA-gated | Default-deny, least open ports, logs, segmentation |
No bypass recipes here — only the why so your rules make sense.
How do I use firewall ideas in real life?
Step 1 — Learn inbound vs outbound with home examples
- Inbound example: A friend tries to reach a game server on your PC — that is inbound to your laptop; the OS firewall or router must allow it, or the packet never arrives.
- Outbound example: Your browser opens Instagram — that is mostly outbound from your phone; most home setups allow outbound by default.
- Why attackers like inbound opens: Anything listening on the internet is a doorbell. Fewer doorbells = smaller attack surface.
- LearnFast Academy Pune lab tip: On a class VM, list listening ports first (
ss -tlnpon Linux) before you invent firewall rules.
Step 2 — Host firewall vs network firewall
- Host: Windows Defender Firewall, macOS firewall,
ufw/firewalldon Linux — protects that machine even if the network is messy. - Network: Home router filters, office firewall appliance, cloud network ACLs — protect many devices at once.
- Best habit: both layers. Example — AWS security group allows 443 to the world for a website, but the host still does not need random admin ports open.
- Nashik exporter office sketch (fictional small firm): warehouse PCs behind the office router; only the mail/VPN gateway is exposed; accounting PCs are not published inbound.
Step 3 — Write rules like a grocery list (vertical)
- Decide the purpose: “Web server needs HTTPS.”
- Allow only that: TCP 443 inbound to the web host.
- Admin access: SSH/RDP only from your IP, a bastion, or after VPN.
- Deny (or leave default-deny) everything else inbound.
- Re-test the service you care about after each change.
- Document who asked for each open port (even a one-line notes file helps).
Ubuntu sketch (lab you own):
sudo ufw allow OpenSSH
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose
Step 4 — Everyday device checklist
- Laptop: leave the OS firewall on; do not disable it “to fix Wi‑Fi” permanently.
- Home router: change default admin password; turn off remote management from the internet if you do not need it.
- GF/BF shared Netflix PC: still keep the OS firewall on — entertainment devices get malware too.
- Jio / ISP router: if you port-forward for a game or camera, write an expiry reminder; remove forwards you no longer use.
- Cloud VM: security group + host firewall together; see the Linux harden guide for order (allow SSH first).
Step 5 — Know the limits of firewalls
- Firewalls do not read your mind about phishing links.
- They do not replace MFA when a password leaks.
- Malware that already runs as your user can often make allowed outbound connections — that is why updates and least privilege still matter.
- Encrypted bad traffic can look like normal HTTPS — firewalls are not magic antivirus.
- Misconfigured “allow all” rules erase the benefit — audit open ports monthly on servers you run.
Step 6 — Pair firewall thinking with cloud and home
- EC2 habit: Security group allow-list is not optional decoration — treat it like a network firewall for that instance.
- Home habit: Guest Wi‑Fi for visitors keeps their devices off your NAS and office laptop VLAN if the router supports it.
- Instagram-on-café story: A firewall on your laptop still helps if a shady hotspot tries odd inbound probes; a VPN (next guides) helps privacy on outbound browsing.
- Monthly 10-minute review: open ports, port forwards, and “who still needs this?”
- Teach one family member the phrase: “If we did not open it on purpose, close it.”
Ravindra Bagale's Tip
💡 Many students say "firewall is on so we are 100% safe". No. A firewall is door control. Stolen password, phishing click, outdated plugin — those arrive inside the door. So layers: firewall + updates + MFA + backup. Never forget!
Ravindra Bagale's Tip – मराठी
💡 खूप students म्हणतात "firewall on आहे म्हणजे 100% safe". नाही. Firewall = दरवाजा control. Password चोरला, phishing click, outdated plugin – हे firewall च्या आत येतात. So layers: firewall + updates + MFA + backup. बिल्कुल विसरू नका!
Ravindra Bagale's Tip – हिंदी
💡 बहुत students कहते हैं "firewall on है मतलब 100% safe". नहीं. Firewall = दरवाज़ा control. Password चोरी, phishing click, outdated plugin – ये firewall के अंदर आते हैं. So layers: firewall + updates + MFA + backup. बिल्कुल मत भूलो!
Quick vocabulary
- Packet — a small unit of network data.
- Port — a numbered door on a device (443 for HTTPS, 22 for SSH).
- Allow list — only named traffic may pass; everything else stays out by default.
- Stateful — the firewall remembers an allowed conversation briefly so replies can return.
Care-take prevention checklist
- Inventory listening ports on machines you administer.
- Default-deny inbound; open only justified ports.
- Never leave RDP/SSH open to the whole internet without a compensating control (MFA, allow-list, bastion).
- Keep host firewall on for laptops.
- Remove old port forwards on the home router.
- Pair cloud security groups with host rules.
- Log and glance at blocked noise on servers you care about.
- Patch the firewall/router firmware itself.
How do I fix common firewall mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
Locked out of SSH after ufw enable |
SSH not allowed first | Use provider console; allow OpenSSH; reload |
| Website works on server but not from phone | Cloud SG or router missing 80/443 | Add only those ports; retest |
| “Firewall is on” but RDP found on Shodan-like scanners | Admin port published to world | Restrict source IP / use VPN; rotate passwords; MFA |
| Game / camera stopped working after router reset | Port forward wiped or ISP CGNAT | Re-add carefully or use vendor relay; avoid permanent wide opens |
| Malware still phoned home | Outbound still allowed by design | Updates, AV, least privilege, DNS filtering — not firewall alone |
Try it at home
On your laptop only, write four lines:
- Is the OS firewall on? (yes/no)
- Which inbound ports did you intentionally open?
- Does your home router allow remote admin from the internet?
- One port forward you can delete because you no longer need it?
Learn it properly
Got it? Firewall = rule-based door. Keep inbound small, host + network both layers, do not open admin ports to the world. A firewall does not replace phishing/MFA. Next: also see the VPN guide — how to keep remote access safe.
समजलं का? Firewall = rule-based दरवाजा. Inbound लहान ठेवा, host + network दोन्ही layers, admin ports world ला open नको. Firewall phishing/MFA replace नाही करतो. आता VPN guide पण बघा – remote access safe कसा ठेवायचा.
समझ में आया? Firewall = rule-based दरवाज़ा. Inbound छोटा रखो, host + network दोनों layers, admin ports world पर open नहीं. Firewall phishing/MFA replace नहीं करता. आगे VPN guide भी देखो – remote access safe कैसे रखें.
Frequently asked questions
What does a firewall do?
It compares network traffic to rules and allows or blocks packets by port, address and direction.
What is the difference between host and network firewalls?
A host firewall protects one device; a network firewall or router filter sits in front of many devices.
Are AWS security groups firewalls?
They are cloud allow-lists that behave like firewalls for instances and work best with a host firewall too.
Will a firewall stop phishing?
No. Phishing tricks people and browsers; you still need awareness, MFA and safe habits.
Why did I lock myself out after enabling ufw?
SSH was probably not allowed before enable. Use the provider console, allow OpenSSH, then reload.
Where are deeper lessons on this site?
Cyber Linux hardening host-firewall lessons and the firewall-types blue-team chapter.