Skip to main content

Firewall

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

What is Firewall?

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy. Depending on its type, it can evaluate addresses, ports, protocols, connection state, or application data. A firewall controls traffic flow. It does not prove user identity, repair vulnerable services, or guarantee that allowed traffic is safe.

Why it matters

A firewall can remove unnecessary network paths and limit communication between systems with different security postures. A default-deny policy also makes each permitted flow an explicit operational decision.

How it works

  1. Define network zones, required traffic flows, rule ownership, and a default action for traffic that has no matching rule.
  2. The firewall observes traffic and compares available packet, connection, or application facts with its ordered policy rules.
  3. It allows, drops, or rejects the traffic, records configured events, and receives regular rule review and testing.

Example

An internet firewall allows HTTPS only to Pomerium. A separate rule lets only Pomerium reach the private application, and all direct internet-to-application traffic is denied.

Pomerium boundary

Pomerium complements a firewall by applying identity-aware and context-aware policy at the application route. Network rules should restrict the upstream service so that a requester cannot bypass Pomerium. Pomerium is not a general network firewall.

Limits and non-claims

  • Allowed traffic can still carry malicious content or exploit a vulnerable application.
  • Encrypted or unsupported protocols can limit the facts that a firewall can inspect.
  • Incorrect, obsolete, or bypassed rules can create unintended access or service failure.

Evaluation checklist

  • Which source, destination, protocol, port, direction, and state does each rule permit?
  • How do rule order, network address translation, IPv6, and overlapping controls change the result?
  • Can an alternate route or direct endpoint bypass the firewall, and do logs prove the effective path?

Sources and further reading

Keep learning

Network and Infrastructure

Perimeter

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo