Ravindra BagaleCourses & study guides Track your progress

Guides

How Does a Firewall Work? (Beginner Explainer)

A firewall is a filter that decides which network traffic may enter or leave a device or network. It matches packets against allow/deny rules (ports, IPs, directions). Host firewalls protect one machine; network firewalls sit on the path for many devices. Firewalls reduce exposure — they do not replace updates, MFA or careful browsing.

Friends! At home a Jio router, on the laptop Windows Firewall, on EC2 a security group — all are firewall concepts. Today in beginner language: inbound vs outbound, host vs network, rules, and the firewall's limit. No bypass recipes — understand defence.

Quick answer

Remember this vertical checklist:

  1. A firewall compares traffic to rules, then allows or blocks.
  2. Inbound = traffic coming toward you; outbound = traffic leaving your device/network.
  3. Default-deny inbound (only open what you need) is the safe habit.
  4. Host firewall = one laptop/server; network firewall / router = many devices.
  5. Cloud “security groups” are firewall-like allow lists for instances.
  6. Firewalls do not stop phishing clicks, stolen passwords or malware that already runs as you.
  7. Order matters: allow remote admin (SSH/RDP) before you tighten rules, or you lock yourself out.

Everyday map:

Phone / laptop OS firewall  → host firewall
Home router / Jio gateway   → network edge filter
AWS security group          → cloud allow-list for one instance
Company perimeter firewall  → shared network control

What do I need before this guide?

  • Curiosity about why some ports are “open” and others are not.
  • Optional lab: a Linux VM you own (see Harden a Linux server checklist).
  • Optional: home router admin page (login only on your network — never share the password).

How does a firewall work (simple flow)?

How a firewall filters traffic Internet traffic hits a firewall. Allowed ports pass to the device; blocked traffic is dropped. Internet many ports Firewall check rules allow / deny Allow e.g. HTTPS Block unexpected packet

Internet traffic hits a firewall. Allowed ports pass through; unexpected inbound traffic is blocked by the rules.

Read the flow as a vertical list:

  1. A packet arrives (or wants to leave).
  2. The firewall reads simple facts: source, destination, port, protocol, direction.
  3. It checks rules from top to bottom (or by priority).
  4. First matching action wins: allow or deny (exact products differ).
  5. Allowed traffic continues; denied traffic is dropped or rejected.
  6. Many firewalls are stateful: they remember a short conversation so return traffic for an allowed session can pass without a separate messy rule.

Your job as a beginner defender: few inbound allows, clear purpose for each open port, and logs when something unexpected hits the wall.

Real incident (public lesson) — exposed remote desktop without a tight firewall

WannaCry (2017) and NotPetya (2017) spread partly because many organisations had Wide-open remote services and weak internal segmentation. Public reporting also repeatedly shows RDP / remote admin left reachable from the whole internet with weak passwords — scanners find them in minutes.

Care-take bullets (defence only):

  1. Do not publish RDP/SSH to 0.0.0.0/0 if you can avoid it.
  2. Prefer VPN + MFA, bastion, or cloud “My IP” rules for admin ports.
  3. Patch border devices and OS quickly.
  4. Segment lab PCs from work-critical systems when you can.
  5. A firewall rule that never existed cannot block what was never filtered — write the allow list on purpose.

Red Team vs Blue Team (high level)

Side Goal (concepts only) What they care about
Red Team Reach a service that should not be public; move laterally if one host falls Open ports, weak admin exposure, flat networks
Blue Team Shrink what is reachable; detect noisy scans; keep admin paths MFA-gated Default-deny, least open ports, logs, segmentation

No bypass recipes here — only the why so your rules make sense.

How do I use firewall ideas in real life?

Step 1 — Learn inbound vs outbound with home examples

  1. Inbound example: A friend tries to reach a game server on your PC — that is inbound to your laptop; the OS firewall or router must allow it, or the packet never arrives.
  2. Outbound example: Your browser opens Instagram — that is mostly outbound from your phone; most home setups allow outbound by default.
  3. Why attackers like inbound opens: Anything listening on the internet is a doorbell. Fewer doorbells = smaller attack surface.
  4. LearnFast Academy Pune lab tip: On a class VM, list listening ports first (ss -tlnp on Linux) before you invent firewall rules.

Step 2 — Host firewall vs network firewall

  1. Host: Windows Defender Firewall, macOS firewall, ufw / firewalld on Linux — protects that machine even if the network is messy.
  2. Network: Home router filters, office firewall appliance, cloud network ACLs — protect many devices at once.
  3. Best habit: both layers. Example — AWS security group allows 443 to the world for a website, but the host still does not need random admin ports open.
  4. Nashik exporter office sketch (fictional small firm): warehouse PCs behind the office router; only the mail/VPN gateway is exposed; accounting PCs are not published inbound.

Step 3 — Write rules like a grocery list (vertical)

  1. Decide the purpose: “Web server needs HTTPS.”
  2. Allow only that: TCP 443 inbound to the web host.
  3. Admin access: SSH/RDP only from your IP, a bastion, or after VPN.
  4. Deny (or leave default-deny) everything else inbound.
  5. Re-test the service you care about after each change.
  6. Document who asked for each open port (even a one-line notes file helps).

Ubuntu sketch (lab you own):

sudo ufw allow OpenSSH
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

Step 4 — Everyday device checklist

  1. Laptop: leave the OS firewall on; do not disable it “to fix Wi‑Fi” permanently.
  2. Home router: change default admin password; turn off remote management from the internet if you do not need it.
  3. GF/BF shared Netflix PC: still keep the OS firewall on — entertainment devices get malware too.
  4. Jio / ISP router: if you port-forward for a game or camera, write an expiry reminder; remove forwards you no longer use.
  5. Cloud VM: security group + host firewall together; see the Linux harden guide for order (allow SSH first).

Step 5 — Know the limits of firewalls

  1. Firewalls do not read your mind about phishing links.
  2. They do not replace MFA when a password leaks.
  3. Malware that already runs as your user can often make allowed outbound connections — that is why updates and least privilege still matter.
  4. Encrypted bad traffic can look like normal HTTPS — firewalls are not magic antivirus.
  5. Misconfigured “allow all” rules erase the benefit — audit open ports monthly on servers you run.

Step 6 — Pair firewall thinking with cloud and home

  1. EC2 habit: Security group allow-list is not optional decoration — treat it like a network firewall for that instance.
  2. Home habit: Guest Wi‑Fi for visitors keeps their devices off your NAS and office laptop VLAN if the router supports it.
  3. Instagram-on-café story: A firewall on your laptop still helps if a shady hotspot tries odd inbound probes; a VPN (next guides) helps privacy on outbound browsing.
  4. Monthly 10-minute review: open ports, port forwards, and “who still needs this?”
  5. Teach one family member the phrase: “If we did not open it on purpose, close it.”

Ravindra Bagale's Tip

💡 Many students say "firewall is on so we are 100% safe". No. A firewall is door control. Stolen password, phishing click, outdated plugin — those arrive inside the door. So layers: firewall + updates + MFA + backup. Never forget!

Quick vocabulary

  1. Packet — a small unit of network data.
  2. Port — a numbered door on a device (443 for HTTPS, 22 for SSH).
  3. Allow list — only named traffic may pass; everything else stays out by default.
  4. Stateful — the firewall remembers an allowed conversation briefly so replies can return.

Care-take prevention checklist

  1. Inventory listening ports on machines you administer.
  2. Default-deny inbound; open only justified ports.
  3. Never leave RDP/SSH open to the whole internet without a compensating control (MFA, allow-list, bastion).
  4. Keep host firewall on for laptops.
  5. Remove old port forwards on the home router.
  6. Pair cloud security groups with host rules.
  7. Log and glance at blocked noise on servers you care about.
  8. Patch the firewall/router firmware itself.

How do I fix common firewall mistakes?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
Locked out of SSH after ufw enable SSH not allowed first Use provider console; allow OpenSSH; reload
Website works on server but not from phone Cloud SG or router missing 80/443 Add only those ports; retest
“Firewall is on” but RDP found on Shodan-like scanners Admin port published to world Restrict source IP / use VPN; rotate passwords; MFA
Game / camera stopped working after router reset Port forward wiped or ISP CGNAT Re-add carefully or use vendor relay; avoid permanent wide opens
Malware still phoned home Outbound still allowed by design Updates, AV, least privilege, DNS filtering — not firewall alone

Try it at home

On your laptop only, write four lines:

  1. Is the OS firewall on? (yes/no)
  2. Which inbound ports did you intentionally open?
  3. Does your home router allow remote admin from the internet?
  4. One port forward you can delete because you no longer need it?

Got it? Firewall = rule-based door. Keep inbound small, host + network both layers, do not open admin ports to the world. A firewall does not replace phishing/MFA. Next: also see the VPN guide — how to keep remote access safe.

Frequently asked questions

What does a firewall do?

It compares network traffic to rules and allows or blocks packets by port, address and direction.

What is the difference between host and network firewalls?

A host firewall protects one device; a network firewall or router filter sits in front of many devices.

Are AWS security groups firewalls?

They are cloud allow-lists that behave like firewalls for instances and work best with a host firewall too.

Will a firewall stop phishing?

No. Phishing tricks people and browsers; you still need awareness, MFA and safe habits.

Why did I lock myself out after enabling ufw?

SSH was probably not allowed before enable. Use the provider console, allow OpenSSH, then reload.

Where are deeper lessons on this site?

Cyber Linux hardening host-firewall lessons and the firewall-types blue-team chapter.