Firewalls
Quick answer
A firewall decides which network connections are allowed to reach a device or leave it, based on rules about address, port, direction and, in some cases, the program involved. It controls access rather than content, and most Australian households already run two without noticing.
Every connection a device makes has a direction, a destination address, a port number identifying the service, and a process that initiated it. A firewall is the component that inspects those properties against a set of rules and permits or refuses the connection. The underlying concept is older than the consumer internet and has not changed: the sophistication lies in what the rules can describe.
Two firewalls are usually in play. One runs on the home router and faces the internet. The other runs on the device itself, as part of the operating system or a security product. They protect against different things, and neither makes the other redundant.
The two positions compared
| Property | Router firewall | Device firewall |
|---|---|---|
| Protects | Everything on the home network | One device, wherever it is |
| Blocks unsolicited inbound traffic | Yes, largely as a side effect of address translation | Yes, by explicit rule |
| Sees traffic between devices on the same network | No | Yes |
| Knows which program made a connection | No | Yes |
| Applies on public Wi-Fi | No | Yes |
| Typical configuration effort | Default is usually adequate | Default is usually adequate |
The row that explains most confusion is the third. A router firewall cannot inspect traffic that never passes through it, so a compromised device on the same network — a visitor's laptop, an unpatched smart appliance — is on the inside of that boundary. The device firewall is what addresses that, which is why operating systems treat public networks more restrictively than networks marked as private.
Inbound and outbound
- Inbound filtering
- Refusing connections initiated from outside. This is the original purpose and is handled well by defaults on both router and device. Its value is that a service listening on the device is simply unreachable from the internet.
- Outbound filtering
- Controlling connections the device initiates. It is what prompts the dialogs asking whether a program may access the network, and in principle it can notice software contacting an unexpected destination. In practice malicious code frequently uses ports and protocols that must stay open, so outbound filtering is a useful signal rather than a barrier.
- Stateful inspection
- Tracking which conversations are already under way, so replies to a connection the device started are allowed while unrelated traffic from the same address is not. Every current firewall does this.
- Application awareness
- Attaching rules to a named program rather than to a port. This is available only on the device, because only the device knows which process opened the socket.
On third-party replacements
The firewalls built into current desktop and mobile operating systems are capable and enabled by default. A firewall included with a security product mainly changes the interface, the logging and the handling of prompts. Replacing a working default is a matter of preference rather than a gap being filled, and running two active filtering products at once can produce conflicts.
What a firewall does not do
The limits are worth stating plainly, because firewall is a reassuring word.
- It does not inspect content. A connection the user initiated to a fraudulent website is permitted, because it is outbound, expected, and encrypted. See phishing.
- It does not identify malicious files. That is the subject of signature detection and behavioural detection.
- It does not help once credentials are given away. An attacker signing in through a service that is meant to be reachable is using an allowed path.
- It does not conceal browsing from an internet provider. That is a separate function, unrelated to filtering.
Port forwarding and the exceptions people create
Most weakening of a home firewall is done deliberately. Port forwarding — instructing the router to pass connections on a given port to a specific device — is used for remote desktop access, security cameras, games and media servers. Each rule creates a deliberate opening, and an opening to a device running outdated software is a common route into home and small-business networks.
Universal Plug and Play allows applications to create such openings without being asked, which is convenient and removes the record of what was opened. Readers who do not need it can usually switch it off in the router's settings, and reviewing the list of existing forwarding rules occasionally is worthwhile: rules created for a device that has since been replaced tend to remain.
The router itself
The firewall is only as trustworthy as the device running it, and home routers are easy to forget. Three things are worth checking once and then rarely: that the administrative password has been changed from the one printed on the label or published in the manual, that remote administration from the internet is switched off unless it is genuinely needed, and that firmware updates are being applied, either automatically or by occasional manual check. A router that no longer receives updates from its manufacturer is a permanent exception to everything else on this page.
A guest network, offered by most current routers, is the simplest way to apply the principle in the second section. Visitors' devices and internet-connected appliances placed on it can reach the internet but not the computers and storage on the main network, which limits what a single compromised device can reach.
Public networks
On a public network the device firewall is the only one present. Modern operating systems prompt for the network type on first connection and apply a stricter profile to public networks, disabling file and printer sharing and refusing discovery requests. Accepting that prompt accurately is the single most useful action a reader takes in a café or an airport. General guidance on using public networks safely is published by the Australian Cyber Security Centre at cyber.gov.au.
Key terms on this page
- Port
- A number identifying a particular service on a device.
- Stateful inspection
- Allowing replies to conversations the device itself began.
- Network address translation
- Sharing one public address among several devices, which incidentally hides them from unsolicited inbound traffic.
- Port forwarding
- A rule passing inbound connections on a chosen port to a specific internal device.