How it works
Rules are written in terms of addresses, ports and protocols: allow 443 from anywhere, allow 22 only from the office, block everything else. Most modern firewalls are stateful, which means they remember outgoing connections and let the replies back in automatically. Home routers do this by default, which is one reason devices at home cannot be reached directly from the internet.
Firewalls come in several forms: software on each machine (Windows Defender Firewall, the macOS firewall, ufw and nftables on Linux), cloud firewall rules and security groups on AWS, Google Cloud and Azure, and hardware appliances at the edge of an office network. Next-generation firewalls also recognise the apps inside the traffic, and a web application firewall (WAF) specialises in attacks on websites.
A sound starting point is to deny everything inbound and open only what each service needs: 80 and 443 for a website, and SSH only from known addresses or through a VPN. Databases should never be open to the whole internet; managed database services usually offer an IP allow list as an extra layer on top of passwords.
Firewall pricing
Free
Firewalls built into Windows, macOS and Linux are free. Hardware and managed firewalls are paid, often as a device plus a yearly security subscription.
Approximate, checked September 2026.What the other tools cost
Firewall vs the alternatives
Related terms
More in Networking
Getting around