True Aspect

Firewalls

Quick answer

A firewall decides which network connections are allowed to reach a device or leave it, based on rules about address, port, direction and, in some cases, the program involved. It controls access rather than content, and most Australian households already run two without noticing.

Every connection a device makes has a direction, a destination address, a port number identifying the service, and a process that initiated it. A firewall is the component that inspects those properties against a set of rules and permits or refuses the connection. The underlying concept is older than the consumer internet and has not changed: the sophistication lies in what the rules can describe.

Two firewalls are usually in play. One runs on the home router and faces the internet. The other runs on the device itself, as part of the operating system or a security product. They protect against different things, and neither makes the other redundant.

The two positions compared

What each firewall is placed to see.
PropertyRouter firewallDevice firewall
ProtectsEverything on the home networkOne device, wherever it is
Blocks unsolicited inbound trafficYes, largely as a side effect of address translationYes, by explicit rule
Sees traffic between devices on the same networkNoYes
Knows which program made a connectionNoYes
Applies on public Wi-FiNoYes
Typical configuration effortDefault is usually adequateDefault is usually adequate

The row that explains most confusion is the third. A router firewall cannot inspect traffic that never passes through it, so a compromised device on the same network — a visitor's laptop, an unpatched smart appliance — is on the inside of that boundary. The device firewall is what addresses that, which is why operating systems treat public networks more restrictively than networks marked as private.

Inbound and outbound

Inbound filtering
Refusing connections initiated from outside. This is the original purpose and is handled well by defaults on both router and device. Its value is that a service listening on the device is simply unreachable from the internet.
Outbound filtering
Controlling connections the device initiates. It is what prompts the dialogs asking whether a program may access the network, and in principle it can notice software contacting an unexpected destination. In practice malicious code frequently uses ports and protocols that must stay open, so outbound filtering is a useful signal rather than a barrier.
Stateful inspection
Tracking which conversations are already under way, so replies to a connection the device started are allowed while unrelated traffic from the same address is not. Every current firewall does this.
Application awareness
Attaching rules to a named program rather than to a port. This is available only on the device, because only the device knows which process opened the socket.

On third-party replacements

The firewalls built into current desktop and mobile operating systems are capable and enabled by default. A firewall included with a security product mainly changes the interface, the logging and the handling of prompts. Replacing a working default is a matter of preference rather than a gap being filled, and running two active filtering products at once can produce conflicts.

What a firewall does not do

The limits are worth stating plainly, because firewall is a reassuring word.

Port forwarding and the exceptions people create

Most weakening of a home firewall is done deliberately. Port forwarding — instructing the router to pass connections on a given port to a specific device — is used for remote desktop access, security cameras, games and media servers. Each rule creates a deliberate opening, and an opening to a device running outdated software is a common route into home and small-business networks.

Universal Plug and Play allows applications to create such openings without being asked, which is convenient and removes the record of what was opened. Readers who do not need it can usually switch it off in the router's settings, and reviewing the list of existing forwarding rules occasionally is worthwhile: rules created for a device that has since been replaced tend to remain.

The router itself

The firewall is only as trustworthy as the device running it, and home routers are easy to forget. Three things are worth checking once and then rarely: that the administrative password has been changed from the one printed on the label or published in the manual, that remote administration from the internet is switched off unless it is genuinely needed, and that firmware updates are being applied, either automatically or by occasional manual check. A router that no longer receives updates from its manufacturer is a permanent exception to everything else on this page.

A guest network, offered by most current routers, is the simplest way to apply the principle in the second section. Visitors' devices and internet-connected appliances placed on it can reach the internet but not the computers and storage on the main network, which limits what a single compromised device can reach.

Public networks

On a public network the device firewall is the only one present. Modern operating systems prompt for the network type on first connection and apply a stricter profile to public networks, disabling file and printer sharing and refusing discovery requests. Accepting that prompt accurately is the single most useful action a reader takes in a café or an airport. General guidance on using public networks safely is published by the Australian Cyber Security Centre at cyber.gov.au.

Key terms on this page

Port
A number identifying a particular service on a device.
Stateful inspection
Allowing replies to conversations the device itself began.
Network address translation
Sharing one public address among several devices, which incidentally hides them from unsolicited inbound traffic.
Port forwarding
A rule passing inbound connections on a chosen port to a specific internal device.