What is Firewall?
A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy. Depending on its type, it can evaluate addresses, ports, protocols, connection state, or application data. A firewall controls traffic flow. It does not prove user identity, repair vulnerable services, or guarantee that allowed traffic is safe.
Why it matters
A firewall can remove unnecessary network paths and limit communication between systems with different security postures. A default-deny policy also makes each permitted flow an explicit operational decision.
How it works
- Define network zones, required traffic flows, rule ownership, and a default action for traffic that has no matching rule.
- The firewall observes traffic and compares available packet, connection, or application facts with its ordered policy rules.
- It allows, drops, or rejects the traffic, records configured events, and receives regular rule review and testing.
Example
An internet firewall allows HTTPS only to Pomerium. A separate rule lets only Pomerium reach the private application, and all direct internet-to-application traffic is denied.
Pomerium boundary
Pomerium complements a firewall by applying identity-aware and context-aware policy at the application route. Network rules should restrict the upstream service so that a requester cannot bypass Pomerium. Pomerium is not a general network firewall.
Limits and non-claims
- Allowed traffic can still carry malicious content or exploit a vulnerable application.
- Encrypted or unsupported protocols can limit the facts that a firewall can inspect.
- Incorrect, obsolete, or bypassed rules can create unintended access or service failure.
Evaluation checklist
- Which source, destination, protocol, port, direction, and state does each rule permit?
- How do rule order, network address translation, IPv6, and overlapping controls change the result?
- Can an alternate route or direct endpoint bypass the firewall, and do logs prove the effective path?
