Both, honestly. It can be software running right on your computer, or it can be an actual physical device sitting between your network and the internet. People talk about “the firewall” like there’s one single kind out there, but there really isn’t.
The basic job stays the same either way, checking traffic and deciding what gets through. What changes is just where that checking actually happens.
Software Firewalls Live on Your Device
A software firewall runs directly on whatever device you’re using. Your laptop sends and receives traffic constantly, and the firewall’s watching those connections before anything gets through. If some app suddenly tries connecting out to the internet on its own, the firewall can block it or just ask you what to do about it. You get that control without needing another piece of hardware sitting around.
This tends to be the practical choice for individual computers since it’s already sitting right there on the thing it’s protecting, so the rules can get pretty specific to that one device. Nothing extra to plug in either, it just runs quietly in the background until you forget it’s even there. There’s one catch though, if the machine itself gets compromised somehow, the firewall’s ability to protect it kind of goes out the window too.
Hardware Firewalls Sit Between Networks
A hardware firewall is its own separate box, usually sitting between your internal network and the internet, checking traffic before it ever reaches the actual computers and phones inside. Your home router probably already has some firewall features built in. Businesses often go with dedicated firewall appliances since they need to handle traffic for a lot of devices all at once.
Location matters a lot here. Instead of protecting just one laptop, this thing’s enforcing rules for an entire network from a single spot.
Can You Use Both
Yeah, and this is where it actually gets interesting. A network can run a hardware firewall at the edge while individual computers still run their own software firewalls on top of that.
They’re doing different jobs really. The hardware one handles traffic moving between networks, the software one focuses on activity happening on the device itself, since traffic that got past the network firewall isn’t automatically safe once it reaches a machine.
For a business, running both just makes sense, honestly I’d rather have the extra layer than bet everything on one firewall catching absolutely everything. At home though, you don’t need to turn your living room into some mini security operations center. A router with decent firewall features plus whatever’s built into your computer is usually plenty.
So Which One Counts as a Firewall
Both do, really. Hardware just describes where it physically lives, software describes one running through a program or operating system feature instead. The more useful question isn’t which type counts as a real firewall, it’s what you’re actually trying to protect. One computer, software makes sense. A whole network, hardware has a clear role there. Want extra separation, just use both.
That’s probably the part worth keeping in mind. A firewall doesn’t need blinking lights on a box to be doing its job. Sometimes it’s just quietly sitting inside your operating system, working away without ever getting in your way.