A firewall sits between your device or network and the traffic trying to get in or out. Its job is pretty simple at first glance. Look at the traffic, check the rules, then decide what happens next.

What Does a Firewall Actually Look At?

Think of network traffic as packets moving between devices. Each packet carries information that helps the firewall understand where it’s going and what kind of connection it belongs to. A firewall can inspect the source address, which identifies where the traffic came from. It can also check the destination address.

Then there’s the port. A port tells the system which service the traffic is trying to reach. For example, web traffic commonly uses ports associated with HTTP or HTTPS. The firewall can decide that traffic heading toward a particular port is acceptable while refusing something else.

Rules Make the Decision

• An allowed connection gets through, provided it matches the conditions set by the rule.

• Blocked traffic goes nowhere useful. The firewall drops it or rejects the connection, depending on how it’s configured.

• Source and destination matter, because a company might trust traffic from one internal network while blocking similar requests from outside.

• A port-based rule can keep unwanted connections away from a service, which is especially handy when that service shouldn’t be publicly reachable.

Stateful Filtering Is Where It Gets Smarter

Older filtering methods can make decisions by looking at individual packets. Stateful firewalls go further. They remember active connections.

Say your laptop starts a connection to a website. The firewall records that connection as part of its state. When the website sends traffic back, the firewall can recognise that the response belongs to a connection your laptop already started. It doesn’t need to treat the response like some random stranger knocking on the door.

Modern Firewalls Inspect More Than Addresses

Network firewalls today can inspect traffic at deeper levels. Some can identify applications rather than relying only on ports. Others inspect the contents of network traffic to detect suspicious patterns.

This is where firewalls become much more useful against threats that aren’t obvious from an address alone. A connection can come from a normally trusted location and still carry something dangerous.

Some systems also use intrusion prevention features. They examine traffic for patterns linked with known attacks and block matching activity. That’s a different layer of filtering, but it works alongside the basic firewall rules.

Why Filtering Rules Need Care

A firewall that’s too open lets unnecessary traffic through. A firewall that’s too strict can break perfectly normal services.

So the goal isn’t to block everything. The goal is to allow traffic that has a legitimate reason to move while stopping connections that don’t belong there.

That sounds straightforward until a real network gets involved. Suddenly there’s an application nobody documented, a server using an unexpected port, or a rule someone added six months ago and forgot about.