Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Firewall (computing)</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Firewall_(computing)"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Firewall_computing rootpage-Firewall_computing skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Firewall (computing)</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p>In <a href="Computing" title="Computing">computing</a>, a <b>firewall</b> is a <a href="Network_security" title="Network security">network security</a> system that <a href="Network_monitoring" title="Network monitoring">monitors</a> and controls incoming and outgoing <a href="Network_traffic" title="Network traffic">network traffic</a> based on configurable security rules.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> A firewall typically establishes a barrier between a trusted network and an untrusted network, such as the <a href="Internet" title="Internet">Internet</a><sup id="cite_ref-Oppliger_1997_94_3-0" class="reference"><a href="#cite_note-Oppliger_1997_94-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> or between several <a href="VLAN" title="VLAN">VLANs</a>. Firewalls can be categorized as network-based or host-based.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>The term <i><a href="Firewall_(construction)" title="Firewall (construction)">firewall</a></i> originally referred to a wall to confine a fire within a line of adjacent buildings.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Later uses refer to similar structures, such as the <a href="Firewall_(engine)" title="Firewall (engine)">metal sheet</a> separating the <a href="Engine" title="Engine">engine</a> compartment of a <a href="Vehicle" title="Vehicle">vehicle</a> or <a href="Aircraft" title="Aircraft">aircraft</a> from the passenger compartment. The term was applied in the 1980s to network technology<sup id="cite_ref-cheskwick1994_5-0" class="reference"><a href="#cite_note-cheskwick1994-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> that emerged when the Internet was fairly new in terms of its global use and connectivity.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> The predecessors to firewalls for network security were <a href="Router_(computing)" title="Router (computing)">routers</a> used in the 1980s. Because they already segregated networks, routers could filter packets crossing them.<sup id="cite_ref-report_unm_7-0" class="reference"><a href="#cite_note-report_unm-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>Before it was used in real-life computing, the term appeared in <a href="John_Badham" title="John Badham">John Badham's</a> 1983 computer‑hacking movie <i><a href="WarGames" title="WarGames">WarGames</a></i>, spoken by the bearded and bespectacled programmer named Paul Richter, which possibly inspired its later use.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p><p>One of the earliest commercially successful firewall and network address translation (NAT) products was the PIX (Private Internet eXchange) Firewall, invented in 1994 by Network Translation Inc., a startup founded and run by John Mayes. The PIX Firewall technology was coded by Brantley Coile as a consultant software developer.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> Recognizing the emerging IPv4 address depletion problem, they designed the PIX to enable organizations to securely connect private networks to the public internet using a limited number of registered IP addresses. The innovative PIX solution quickly gained industry acclaim, earning the prestigious "Hot Product of the Year" award from Data Communications Magazine in January 1995. Cisco Systems, seeking to expand into the rapidly growing network security market, subsequently acquired Network Translation Inc. in November 1995 to obtain the rights to the PIX technology. The PIX became one of Cisco's flagship firewall product lines before eventually being succeeded by the Adaptive Security Appliance (ASA) platform introduced in 2005.
</p>
<div class="mw-heading mw-heading2"><h2 id="Types_of_firewalls">Types of firewalls</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">See also: <a href="Computer_security" title="Computer security">Computer security</a></div>
<p>Firewalls are categorized as a network-based or a host-based system. Network-based firewalls are positioned between two or more networks, typically between the <a href="Local_area_network" title="Local area network">local area network (LAN)</a> and <a href="Wide_area_network" title="Wide area network">wide area network (WAN)</a>,<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> their basic function being to control the flow of data between connected networks. They are either a <a href="Software_appliance" title="Software appliance">software appliance</a> running on general-purpose hardware, a <a href="Computer_appliance#Types_of_appliances" title="Computer appliance">hardware appliance</a> running on special-purpose hardware, or a <a href="Virtual_appliance" title="Virtual appliance">virtual appliance</a> running on a virtual host controlled by a <a href="Hypervisor" title="Hypervisor">hypervisor</a>. Firewall appliances may also offer non-firewall functionality, such as <a href="DHCP" class="mw-redirect" title="DHCP">DHCP</a><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> or <a href="VPN" class="mw-redirect" title="VPN">VPN</a><sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> services. Host-based firewalls are deployed directly on the <a href="Host_(network)" title="Host (network)">host</a> itself to control network traffic or other computing resources.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> This can be a <a href="Daemon_(computing)" title="Daemon (computing)">daemon</a> or <a href="Windows_service" title="Windows service">service</a> as a part of the <a href="Operating_system" title="Operating system">operating system</a> or an <a href="Endpoint_security" title="Endpoint security">agent application</a> for protection.
</p>

<div class="mw-heading mw-heading3"><h3 id="Packet_filter">Packet filter</h3></div>
<p>The first reported type of network firewall is called a <a href="PF_(firewall)" title="PF (firewall)">packet filter</a> which inspects packets transferred between computers. The firewall maintains an <a href="Access-control_list" title="Access-control list">access-control list</a> which dictates what packets will be looked at and what action should be applied, if any, with the default action set to silent discard. Three basic actions regarding the packet consist of a silent discard, discard with <a href="Internet_Control_Message_Protocol" title="Internet Control Message Protocol">Internet Control Message Protocol</a> or <a href="TCP_reset_attack" title="TCP reset attack">TCP reset</a> response to the sender, and forward to the next hop.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> Packets may be filtered by source and destination <a href="Network_address" title="Network address">IP addresses</a>, protocol, or source and destination <a href="Port_(computer_networking)" title="Port (computer networking)">ports</a>. The bulk of Internet communication in 20th and early 21st century used either <a href="Transmission_Control_Protocol" title="Transmission Control Protocol">Transmission Control Protocol</a> (TCP) or <a href="User_Datagram_Protocol" title="User Datagram Protocol">User Datagram Protocol</a> (UDP) in conjunction with <a href="List_of_TCP_and_UDP_port_numbers" title="List of TCP and UDP port numbers">well-known ports</a>, enabling firewalls of that era to distinguish between specific types of traffic such as web browsing, remote printing, email transmission, and file transfers.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-cheswick2003_18-0" class="reference"><a href="#cite_note-cheswick2003-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>The first paper published on firewall technology was in 1987 when engineers from <a href="Digital_Equipment_Corporation" title="Digital Equipment Corporation">Digital Equipment Corporation</a> (DEC) developed filter systems known as packet filter firewalls. At <a href="Bell_Labs" title="Bell Labs">AT&amp;T Bell Labs</a>, <a href="William_Cheswick" title="William Cheswick">Bill Cheswick</a> and <a href="Steven_M._Bellovin" title="Steven M. Bellovin">Steve Bellovin</a> continued their research in packet filtering and developed a working model for their own company based on their original first-generation architecture.<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> In 1992, Steven McCanne and
Van Jacobson released a paper on <a href="Berkeley_Packet_Filter" title="Berkeley Packet Filter">BSD Packet Filter</a> (BPF) while at <a href="Lawrence_Berkeley_Laboratory" class="mw-redirect" title="Lawrence Berkeley Laboratory">Lawrence Berkeley Laboratory</a>.<sup id="cite_ref-bpf93_20-0" class="reference"><a href="#cite_note-bpf93-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Connection_tracking">Connection tracking</h3></div>

<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Stateful_firewall" title="Stateful firewall">Stateful firewall</a></div>
<p>From 1989–1990, three colleagues from <a href="AT%26T_Bell_Laboratories" class="mw-redirect" title="AT&amp;T Bell Laboratories">AT&amp;T Bell Laboratories</a>, Dave Presotto, Janardan Sharma, and Kshitij Nigam, developed the second generation of firewalls, calling them <a href="Circuit-level_gateway" title="Circuit-level gateway">circuit-level gateways</a>.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</p><p>Second-generation firewalls perform the work of their first-generation predecessors but also maintain knowledge of specific conversations between endpoints by remembering which port number the two <a href="IP_address" title="IP address">IP addresses</a> are using at layer 4 (<a href="Transport_layer" title="Transport layer">transport layer</a>) of the <a href="OSI_model" title="OSI model">OSI model</a> for their conversation, allowing examination of the overall exchange between the nodes.<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Application_layer">Application layer</h3></div>
<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Application_firewall" title="Application firewall">Application firewall</a></div>
<p><a href="Marcus_Ranum" class="mw-redirect" title="Marcus Ranum">Marcus Ranum</a>, Wei Xu, and Peter Churchyard released an application firewall known as Firewall Toolkit (FWTK) in October 1993.<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup> This became the basis for Gauntlet firewall at <a href="Trusted_Information_Systems" title="Trusted Information Systems">Trusted Information Systems</a>.<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p><p>The key benefit of <a href="Application_layer" title="Application layer">application layer</a> filtering is that it can understand certain applications and protocols such as <a href="File_Transfer_Protocol" title="File Transfer Protocol">File Transfer Protocol</a> (FTP), <a href="Domain_Name_System" title="Domain Name System">Domain Name System</a> (DNS), or <a href="Hypertext_Transfer_Protocol" class="mw-redirect" title="Hypertext Transfer Protocol">Hypertext Transfer Protocol</a> (HTTP). This allows it to identify unwanted applications or services using a non standard port, or detect if an allowed protocol is being abused.<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup> It can also provide unified security management including enforced <a href="DNS_over_HTTPS" title="DNS over HTTPS">encrypted DNS</a> and <a href="Virtual_private_network" title="Virtual private network">virtual private networking</a>.<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup>
</p><p>As of 2012, the <a href="Next-generation_firewall" title="Next-generation firewall">next-generation firewall</a> provides a wider range of inspection at the application layer, extending <a href="Deep_packet_inspection" title="Deep packet inspection">deep packet inspection</a> functionality to include, but is not limited to:
</p>
<ul><li><a href="Web_filtering" class="mw-redirect" title="Web filtering">Web filtering</a></li>
<li><a href="Intrusion_prevention_system" class="mw-redirect" title="Intrusion prevention system">Intrusion prevention systems</a></li>
<li><a href="Identity_management" class="mw-redirect" title="Identity management">User identity management</a></li>
<li><a href="Web_application_firewall" title="Web application firewall">Web application firewall</a></li>
<li>Content inspection and heuristic analysis<sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup></li>
<li><a href="TLS_termination_proxy" title="TLS termination proxy">TLS Inspection</a></li></ul>
<div class="mw-heading mw-heading4"><h4 id="Endpoint_specific">Endpoint specific</h4></div>
<p>Endpoint-based application firewalls function by determining whether a process should accept any given connection. Application firewalls filter connections by examining the process ID of <a href="Data_packets" class="mw-redirect" title="Data packets">data packets</a> against a rule set for the local process involved in the data transmission. Application firewalls accomplish their function by hooking into <a href="Network_socket" title="Network socket">socket</a> calls to filter the connections between the <a href="Application_layer" title="Application layer">application layer</a> and the lower layers. Application firewalls that hook into socket calls are also referred to as socket filters.
</p>
<div class="mw-heading mw-heading2"><h2 id="Firewall_Policies">Firewall Policies</h2></div>
<p>At the core of a firewall's operation are the policies that govern its decision-making process. These policies, collectively known as firewall rules, are the specific guidelines that determine the traffic allowed or blocked across a network's boundaries.<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-auto_33-0" class="reference"><a href="#cite_note-auto-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
</p><p>Firewall rules are based on the evaluation of network packets against predetermined security criteria. A network packet, which carries data across networks, must match certain attributes defined in a rule to be allowed through the firewall. These attributes commonly include:
</p>
<ul><li><b>Direction</b>: Inbound or outbound traffic</li>
<li><b>Source</b>: Where the traffic originates (<a href="IP_address" title="IP address">IP address, range, network</a>, or zone)</li>
<li><b>Destination</b>: Where the traffic is headed (<a href="IP_address" title="IP address">IP address, range, network</a>, or zone)</li>
<li><b>Port</b>: Network ports specific to various services (e.g., port 80 for <a href="HTTP" title="HTTP">HTTP</a>)</li>
<li><b>Protocol</b>: The type of network protocol (e.g., <a href="Transmission_Control_Protocol" title="Transmission Control Protocol">TCP</a>, <a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a>, <a href="Internet_Control_Message_Protocol" title="Internet Control Message Protocol">ICMP</a>)</li>
<li><b>Applications</b>: L7 inspection or grouping av services.</li>
<li><b>Action</b>: Whether to allow, deny, drop, or require further inspection for the traffic</li></ul>
<div class="mw-heading mw-heading3"><h3 id="Zones">Zones</h3></div>
<p>Zones are logical segments within a network that group together devices with similar security requirements. By partitioning a network into zones, such as "<a href="Operational_technology" title="Operational technology">Technical</a>", "<a href="Wide_area_network" title="Wide area network">WAN</a>", "<a href="Local_area_network" title="Local area network">LAN</a>", "<a href="Wide_area_network" title="Wide area network">Public</a>," "<a href="Private_network" title="Private network">Private</a>," "<a href="DMZ_(computing)" title="DMZ (computing)">DMZ</a>", and "<a href="Wireless_network" title="Wireless network">Wireless</a>," administrators can enforce policies that control the flow of traffic between them. Each zone has its own level of trust and is governed by specific firewall rules that regulate the ingress and egress of data.
</p><p>A typical default is to allow all traffic from LAN to WAN, and to drop all traffic from WAN to LAN.
</p>
<div class="mw-heading mw-heading3"><h3 id="Services">Services</h3></div>
<p>In networking terms, services are specific functions typically identified by a network port and protocol. Common examples include HTTP/HTTPS (web traffic) on ports 80 and 443, FTP (file transfer) on port 21, and SMTP (email) on port 25. Services are the engines behind the applications users depend on. From a security aspect, controlling access to services is crucial because services are common targets for exploitation. Firewalls employ rules that stipulate which services should be accessible, to whom, and in what context. For example, a firewall might be configured to block incoming FTP requests to prevent unauthorized file uploads but allow outgoing HTTPS requests for web browsing.
</p>
<div class="mw-heading mw-heading3"><h3 id="Applications">Applications</h3></div>
<p>Applications refer to the software systems that users interact with while on the network. They can range from web browsers and email clients to complex database systems and cloud-based services. In network security, applications are important because different types of traffic can pose varying security risks. Thus, firewall rules can be crafted to identify and control traffic based on the application generating or receiving it. By using application awareness, firewalls can allow, deny, or limit traffic for specific applications according to organizational policies and compliance requirements, thereby mitigating potential threats from vulnerable or undesired applications.
</p><p>Application can both be a grouping of services, or a <a href="OSI_model" title="OSI model">L7 inspection</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="USER_ID">USER ID</h3></div>
<p>Implementing firewall rules based on IP addresses alone is often insufficient due to the dynamic nature of user location and device usage.<sup id="cite_ref-auto_33-1" class="reference"><a href="#cite_note-auto-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup> User ID will be translate to a IP address.
</p><p>This is where the concept of "User ID" makes a significant impact. User ID allows firewall rules to be crafted based on individual user identities, rather than just fixed source or destination IP addresses. This enhances security by enabling more granular control over who can access certain network resources, regardless of where they are connecting from or what device they are using.
</p><p>The User ID technology is typically integrated into firewall systems through the use of directory services such as <a href="Active_Directory" title="Active Directory">Active Directory</a>, <a href="Lightweight_Directory_Access_Protocol" title="Lightweight Directory Access Protocol">LDAP</a>, <a href="RADIUS" title="RADIUS">RADIUS</a> or <a href="TACACS" title="TACACS">TACACS+</a>. These services link the user's login information to their network activities. By doing this, the firewall can apply rules and policies that correspond to user groups, roles, or individual user accounts instead of purely relying on the network topology.
</p>
<div class="mw-heading mw-heading4"><h4 id="Example_of_Using_User_ID_in_Firewall_Rules">Example of Using User ID in Firewall Rules</h4></div>
<p>Consider a school that wants to restrict access to a <a href="Social_media" title="Social media">social media</a> server from students. They can create a rule in the firewall that utilises User ID information to enforce this policy.
</p>
<ol><li>Directory Service Configuration — First, the firewall must be configured to communicate with the directory service that stores user group memberships. In this case, an <a href="Active_Directory" title="Active Directory">Active Directory server.</a></li>
<li>User Identification — The firewall maps network traffic to specific user IDs by interpreting authentication logs. When a user logs on, the firewall associates that login with the user's <a href="IP_address" title="IP address">IP address</a>.</li>
<li>Define User Groups — Within the firewall's management interface, define user groups based on the directory service. For example, create groups such as "Students".</li>
<li>Create Firewall Rule:
<ul><li>Source: User ID (e.g., Students)</li>
<li>Destination: list of <a href="IP_address" title="IP address">IP addresses</a></li>
<li>Service/Application: Allowed services (e.g., <a href="HTTP" title="HTTP">HTTP</a>, <a href="HTTPS" title="HTTPS">HTTPS</a>)</li>
<li>Action: Deny</li></ul></li>
<li>Implement Default Allow Rule:
<ul><li>Source: <a href="Local_area_network" title="Local area network">LAN</a> zone</li>
<li>Destination: <a href="Wide_area_network" title="Wide area network">WAN</a> zone</li>
<li>Service/Application: Any</li>
<li>Action: Allow</li></ul></li></ol>
<p>With this setup, only users who authenticate and are identified as members of "Students" are denied to access <a href="Social_media" title="Social media">social media</a> servers. All other traffic, starting from LAN interfaces, will be allowed.
</p>
<div class="mw-heading mw-heading2"><h2 id="Most_common_firewall_log_types">Most common firewall log types</h2></div>
<p><b>Traffic Logs:</b>
</p>
<ul><li><b>Description:</b> Traffic logs record comprehensive details about data traversing the network. This includes source and destination IP addresses, port numbers, protocols used, and the action taken by the firewall (e.g., allow, drop, or reject).</li>
<li><b>Significance:</b> Essential for network administrators to analyze and understand the patterns of communication between devices, aiding in troubleshooting and optimizing network performance.</li></ul>
<p><b>Threat Prevention Logs:</b>
</p>
<ul><li><b>Description:</b> Logs specifically designed to capture information related to security threats. This encompasses alerts from intrusion prevention systems (IPS), antivirus events, anti-bot detections, and other threat-related data.</li>
<li><b>Significance:</b> Vital for identifying and responding to potential security breaches, helping security teams stay proactive in safeguarding the network.</li></ul>
<p><b>Audit Logs:</b>
</p>
<ul><li><b>Description:</b> Logs that record administrative actions and changes made to the firewall configuration. These logs are critical for tracking changes made by administrators for security and compliance purposes.</li>
<li><b>Significance:</b> Supports auditing and compliance efforts by providing a detailed history of administrative activities, aiding in investigations and ensuring adherence to security policies.</li></ul>
<p><b>Event Logs:</b>
</p>
<ul><li><b>Description:</b> General event logs that capture a wide range of events occurring on the firewall, helping administrators monitor and troubleshoot issues.</li>
<li><b>Significance:</b> Provides a holistic view of firewall activities, facilitating the identification and resolution of any anomalies or performance issues within the network infrastructure.</li></ul>
<p><b>Session Logs:</b>
</p>
<ul><li><b>Description:</b> Logs that provide information about established network sessions, including session start and end times, data transfer rates, and associated user or device information.</li>
<li><b>Significance:</b> Useful for monitoring network sessions in real-time, identifying abnormal activities, and optimizing network performance.</li></ul>
<p><b>DDoS Mitigation Logs:</b>
</p>
<ul><li><b>Description:</b> Logs that record events related to Distributed Denial of Service (DDoS) attacks, including mitigation actions taken by the firewall to protect the network.</li>
<li><b>Significance:</b> Critical for identifying and mitigating DDoS attacks promptly, safeguarding network resources and ensuring uninterrupted service availability.</li></ul>
<p><b>Geo-location Logs:</b>
</p>
<ul><li><b>Description:</b> Logs that capture information about the geographic locations of network connections. This can be useful for monitoring and controlling access based on geographical regions.</li>
<li><b>Significance:</b> Aids in enhancing security by detecting and preventing suspicious activities originating from specific geographic locations, contributing to a more robust defense against potential threats.</li></ul>
<p><b>URL Filtering Logs:</b>
</p>
<ul><li><b>Description:</b> Records data related to web traffic and URL filtering. This includes details about blocked and allowed URLs, as well as categories of websites accessed by users.</li>
<li><b>Significance:</b> Enables organizations to manage internet access, enforce acceptable use policies, and enhance overall network security by monitoring and controlling web activity.</li></ul>
<p><b>User Activity Logs:</b>
</p>
<ul><li><b>Description:</b> Logs that capture user-specific information, such as authentication events, user login/logout details, and user-specific traffic patterns.</li>
<li><b>Significance:</b> Aids in tracking user behavior, ensuring accountability, and providing insights into potential security incidents involving specific users.</li></ul>
<p><b>VPN Logs:</b>
</p>
<ul><li><b>Description:</b> Information related to Virtual Private Network (VPN) connections, including events like connection and disconnection, tunnel information, and VPN-specific errors.</li>
<li><b>Significance:</b> Crucial for monitoring the integrity and performance of VPN connections, ensuring secure communication between remote users and the corporate network.</li></ul>
<p><b>System Logs:</b>
</p>
<ul><li><b>Description:</b> Logs that provide information about the overall health, status, and configuration changes of the firewall system. This may include logs related to high availability (HA), software updates, and other system-level events.</li>
<li><b>Significance:</b> Essential for maintaining the firewall infrastructure, diagnosing issues, and ensuring the system operates optimally.</li></ul>
<p><b>Compliance Logs:</b>
</p>
<ul><li><b>Description:</b> Logs specifically focused on recording events relevant to regulatory compliance requirements. This may include activities ensuring compliance with industry standards or legal mandates.</li>
<li><b>Significance:</b> Essential for organizations subject to specific regulations, helping to demonstrate adherence to compliance standards and facilitating audit processes.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Configuration">Configuration</h2></div>
<p>Setting up a firewall is a complex and error-prone task. A network may face security issues due to configuration errors.<sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>
</p><p>Firewall policies are typically configured according to the type of network in use, such as public or private environments. Administrators define rules that permit or restrict traffic in order to reduce exposure to threats like unauthorized access, malware, or other forms of cyberattack.<sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup>
</p><p><br>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */


.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}


/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 20em;">
<ul><li><a href="Air_gap_(networking)" title="Air gap (networking)">Air gap (networking)</a></li>
<li><a href="Distributed_firewall" title="Distributed firewall">Distributed firewall</a></li>
<li><a href="DMZ_(computing)" title="DMZ (computing)">DMZ (computing)</a></li>
<li><a href="Firewall_pinhole" title="Firewall pinhole">Firewall pinhole</a></li>
<li><i><a href="Firewalls_and_Internet_Security" title="Firewalls and Internet Security">Firewalls and Internet Security</a></i></li>
<li><a href="Golden_Shield_Project" title="Golden Shield Project">Golden Shield Project</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a></li>
<li><a href="Mobile_security#Security_software" title="Mobile security">Mobile security §&nbsp;Security software</a></li>
<li><a href="Windows_Firewall" title="Windows Firewall">Windows Firewall</a></li></ul>
</div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFBoudriga2010" class="citation book cs1">Boudriga, Noureddine (2010). <span class="id-lock-limited" title="Free access subject to limited trial, subscription normally required"><a rel="nofollow" class="external text" href="https://archive.org/details/securitymobileco00boud"><i>Security of mobile communications</i></a></span>. Boca Raton: CRC Press. pp.&nbsp;<a rel="nofollow" class="external text" href="https://archive.org/details/securitymobileco00boud/page/n66">32</a>–33. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0849379420</bdi>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite id="CITEREFMacfarlaneBuchananEkonomouUthmani2012" class="citation journal cs1">Macfarlane, Richard; Buchanan, William; Ekonomou, Elias; Uthmani, Omair; Fan, Lu; Lo, Owen (2012). <a rel="nofollow" class="external text" href="https://linkinghub.elsevier.com/retrieve/pii/S0167404811001192">"Formal security policy implementations in network firewalls"</a>. <i>Computers &amp; Security</i>. <b>31</b> (2): <span class="nowrap">253–</span>270. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.cose.2011.10.003">10.1016/j.cose.2011.10.003</a>.</cite></span>
</li>
<li id="cite_note-Oppliger_1997_94-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-Oppliger_1997_94_3-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFOppliger1997" class="citation journal cs1">Oppliger, Rolf (May 1997). <a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F253769.253802">"Internet Security: FIREWALLS and BEYOND"</a>. <i>Communications of the ACM</i>. <b>40</b> (5): 94. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F253769.253802">10.1145/253769.253802</a></span>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:15271915">15271915</a>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFCanavan2001" class="citation book cs1">Canavan, John E. (2001). <i>Fundamentals of Network Security</i> (1st&nbsp;ed.). Boston, MA: Artech House. p.&nbsp;212. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9781580531764</bdi>.</cite></span>
</li>
<li id="cite_note-cheskwick1994-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-cheskwick1994_5-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFCheswickBellovin1994" class="citation book cs1"><a href="William_Cheswick" title="William Cheswick">Cheswick, William R.</a>; <a href="Steven_M._Bellovin" title="Steven M. Bellovin">Bellovin, Steven M.</a> (1994). <i><a href="Firewalls_and_Internet_Security" title="Firewalls and Internet Security">Firewalls and Internet Security</a>: Repelling The Wily Hacker</i>. Addison-Wesley. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0201633573</bdi>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite id="CITEREFLiska2014" class="citation book cs1">Liska, Allan (Dec 10, 2014). <i>Building an Intelligence-Led Security Program</i>. Syngress. p.&nbsp;3. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0128023709</bdi>.</cite></span>
</li>
<li id="cite_note-report_unm-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-report_unm_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFInghamForrest2002" class="citation web cs1">Ingham, Kenneth; Forrest, Stephanie (2002). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20060902171316/http://www.cs.unm.edu/~treport/tr/02-12/firewall.pdf">"A History and Survey of Network Firewalls"</a> <span class="cs1-format">(PDF)</span>. Archived from <a rel="nofollow" class="external text" href="http://www.cs.unm.edu/~treport/tr/02-12/firewall.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2006-09-02<span class="reference-accessdate">. Retrieved <span class="nowrap">2011-11-25</span></span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFBoren2019" class="citation web cs1">Boren, Jacob (2019-11-24). <a rel="nofollow" class="external text" href="https://screenrant.com/80s-sci-fi-movies-predicted-the-future/">"10 Times '80s Sci-Fi Movies Predicted The Future"</a>. <i>ScreenRant</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-03-04</span></span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite id="CITEREFMayes2022" class="citation web cs1">Mayes, John (2022-11-24). <a rel="nofollow" class="external text" href="http://www.jma.com/nti.html">"NTI - JMA"</a>. <i>Wikipedia</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-03-04</span></span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFNaveen" class="citation web cs1">Naveen, Sharanya. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160521201820/https://www.paloaltonetworks.com/documentation/glossary/what-is-a-firewall">"Firewall"</a>. Archived from <a rel="nofollow" class="external text" href="https://www.paloaltonetworks.com/documentation/glossary/what-is-a-firewall">the original</a> on 21 May 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">7 June</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/firewall-as-a-dhcp-server-and-client.html">"Firewall as a DHCP Server and Client"</a>. <i>Palo Alto Networks</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2016-02-08</span></span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.shorewall.net/dhcp.htm">"DHCP"</a>. <i>www.shorewall.net</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2016-02-08</span></span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.techopedia.com/definition/30753/vpn-firewall">"What is a VPN Firewall? – Definition from Techopedia"</a>. <i>Techopedia.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2016-02-08</span></span>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite id="CITEREFVacca2009" class="citation book cs1">Vacca, John R. (2009). <i>Computer and information security handbook</i>. Amsterdam: Elsevier. p.&nbsp;355. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9780080921945</bdi>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://personalfirewall.comodo.com/what-is-firewall.html">"What is Firewall?"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2015-02-12</span></span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite id="CITEREFPeltierPeltier2007" class="citation book cs1">Peltier, Justin; Peltier, Thomas R. (2007). <i>Complete Guide to CISM Certification</i>. Hoboken: CRC Press. p.&nbsp;210. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9781420013252</bdi>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.skullbox.net/tcpudp.php">"TCP vs. UDP&nbsp;: The Difference Between them"</a>. <i>www.skullbox.net</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2018-04-09</span></span>.</cite></span>
</li>
<li id="cite_note-cheswick2003-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-cheswick2003_18-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFCheswickBellovinRubin2003" class="citation book cs1">Cheswick, William R.; Bellovin, Steven M.; Rubin, Aviel D. (2003). <i><a href="Firewalls_and_Internet_Security" title="Firewalls and Internet Security">Firewalls and Internet Security</a> repelling the wily hacker</i> (2&nbsp;ed.). Addison-Wesley Professional. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9780201634662</bdi>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite id="CITEREFInghamForrest2002" class="citation web cs1">Ingham, Kenneth; Forrest, Stephanie (2002). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20060902171316/http://www.cs.unm.edu/~treport/tr/02-12/firewall.pdf">"A History and Survey of Network Firewalls"</a> <span class="cs1-format">(PDF)</span>. p.&nbsp;4. Archived from <a rel="nofollow" class="external text" href="http://www.cs.unm.edu/~treport/tr/02-12/firewall.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2006-09-02<span class="reference-accessdate">. Retrieved <span class="nowrap">2011-11-25</span></span>.</cite></span>
</li>
<li id="cite_note-bpf93-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-bpf93_20-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFMcCanneJacobson1992" class="citation web cs1">McCanne, Steven; Jacobson, Van (1992-12-19). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20000916155334/http://www.tcpdump.org/papers/bpf-usenix93.pdf">"The BSD Packet Filter: A New Architecture for User-level Packet Capture"</a> <span class="cs1-format">(PDF)</span>. Archived from <a rel="nofollow" class="external text" href="http://www.tcpdump.org/papers/bpf-usenix93.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2000-09-16.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFMcCanneJacobson1993" class="citation web cs1">McCanne, Steven; Jacobson, Van (January 1993). <a rel="nofollow" class="external text" href="https://www.usenix.org/conference/usenix-winter-1993-conference/bsd-packet-filter-new-architecture-user-level-packet">"The BSD Packet Filter: A New Architecture for User-level Packet Capture"</a>. <a href="USENIX" title="USENIX">USENIX</a>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite id="CITEREFM._Afshar_AlamTamanna_SiddiquiK._R._Seeja2013" class="citation book cs1">M. Afshar Alam; Tamanna Siddiqui; K. R. Seeja (2013). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=TnJk09xmdFsC&amp;pg=PA513"><i>Recent Developments in Computing and Its Applications</i></a>. I. K. International Pvt Ltd. p.&nbsp;513. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-93-80026-78-7</bdi>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.tech-faq.com/firewall.html">"Firewalls"</a>. MemeBridge<span class="reference-accessdate">. Retrieved <span class="nowrap">13 June</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.avolio.com/papers/FWTKv1.0Announcement.html">"Firewall toolkit V1.0 release"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2018-12-28</span></span>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite id="CITEREFJohn_Pescatore2008" class="citation web cs1">John Pescatore (October 2, 2008). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160429131516/http://blogs.gartner.com/john_pescatore/2008/10/02/this-week-in-network-security-history-the-firewall-toolkit/">"This Week in Network Security History: The Firewall Toolkit"</a>. Archived from <a rel="nofollow" class="external text" href="https://blogs.gartner.com/john_pescatore/2008/10/02/this-week-in-network-security-history-the-firewall-toolkit/">the original</a> on April 29, 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">2018-12-28</span></span>.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite id="CITEREFMarcus_J._RanumFrederick_Avolio" class="citation web cs1">Marcus J. Ranum; Frederick Avolio. <a rel="nofollow" class="external text" href="http://www.avolio.com/papers/fwtk-history.html">"FWTK history"</a>.</cite></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.cloudflare.com/learning/ddos/what-is-layer-7/">"What is Layer 7? How Layer 7 of the Internet Works"</a>. <i>Cloudflare</i><span class="reference-accessdate">. Retrieved <span class="nowrap">Aug 29,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.checkpoint.com/cyber-hub/network-security/what-is-firewall/5-firewall-features-you-must-have/">"5 Firewall Features you Must-Have"</a>. <i>Check Point Software</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-08</span></span>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite id="CITEREFStanfield2019" class="citation web cs1">Stanfield, Nathan (2019-12-04). <a rel="nofollow" class="external text" href="https://www.stanfieldit.com/11-firewall-features/">"11 Firewall Features You Can't Live Without"</a>. <i>Stanfield IT</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-08</span></span>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://safing.io/portmaster/">"Safing Portmaster"</a>. <i>safing.io</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-08</span></span>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite id="CITEREFLiangKim2022" class="citation book cs1">Liang, Junyan; Kim, Yoohwan (2022). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/9720435"><i>Evolution of Firewalls: Toward Securer Network Using Next Generation Firewall</i></a>. pp.&nbsp;<span class="nowrap">0752–</span>0759. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FCCWC54503.2022.9720435">10.1109/CCWC54503.2022.9720435</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-6654-8303-2</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">2024-02-02</span></span>.</cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy">"Policy"</a>. <i>docs.paloaltonetworks.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2024-11-21</span></span>.</cite></span>
</li>
<li id="cite_note-auto-33"><span class="mw-cite-backlink">^ <a href="#cite_ref-auto_33-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-auto_33-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.juniper.net/documentation/us/en/software/nm-apps24.1/junos-space-security-director/topics/task/junos-space-firewall-policy-rule-creating.html">"Creating Firewall Policy Rules | Juniper Networks"</a>. <i>www.juniper.net</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2024-11-21</span></span>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id">"User-ID"</a>. <i>docs.paloaltonetworks.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2024-11-21</span></span>.</cite></span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-35">^</a></b></span> <span class="reference-text"><cite id="CITEREFVoronkovIwayaMartucciLindskog2018" class="citation journal cs1">Voronkov, Artem; Iwaya, Leonardo Horn; Martucci, Leonardo A.; Lindskog, Stefan (2018-01-12). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1145/3130876">"Systematic Literature Review on Usability of Firewall Configuration"</a></span>. <i>ACM Computing Surveys</i>. <b>50</b> (6): <span class="nowrap">1–</span>35. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3130876">10.1145/3130876</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0360-0300">0360-0300</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:6570517">6570517</a>.</cite></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.fortinet.com/resources/cyberglossary/firewall-configuration">"What is Firewall Configuration and Why is it Important?"</a>. <i>Fortinet</i>.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="http://docstore.mik.ua/univercd/cc/td/doc/product/iaabu/centri4/user/scf4ch3.htm">Evolution of the Firewall Industry</a> – discusses different architectures, how packets are processed and provides a timeline of the evolution.</li>
<li><a rel="nofollow" class="external text" href="http://www.cs.unm.edu/~treport/tr/02-12/firewall.pdf">A History and Survey of Network Firewalls</a> – provides an overview of firewalls at various ISO levels, with references to original papers where early firewall work was reported.</li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Information_security92" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="3"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div id="Information_security92" style="font-size:114%;margin:0 4em"><a href="Information_security" title="Information security">Information security</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Threat_(computer)" class="mw-redirect" title="Threat (computer)">Threats</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Advanced_persistent_threat" title="Advanced persistent threat">Advanced persistent threat</a></li>
<li><a href="Arbitrary_code_execution" title="Arbitrary code execution">Arbitrary code execution</a></li>
<li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoors</a></li>
<li>Bombs
<ul><li><a href="Fork_bomb" title="Fork bomb">Fork</a></li>
<li><a href="Logic_bomb" title="Logic bomb">Logic</a></li>
<li><a href="Time_bomb_(software)" title="Time bomb (software)">Time</a></li>
<li><a href="Zip_bomb" title="Zip bomb">Zip</a></li></ul></li>
<li><a href="Hardware_backdoor" title="Hardware backdoor">Hardware backdoors</a></li>
<li><a href="Code_injection" title="Code injection">Code injection</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Cross-site_scripting" title="Cross-site scripting">Cross-site scripting</a></li>
<li><a href="Cross-site_leaks" title="Cross-site leaks">Cross-site leaks</a></li>
<li><a href="DOM_clobbering" title="DOM clobbering">DOM clobbering</a></li>
<li><a href="History_sniffing" title="History sniffing">History sniffing</a></li>
<li><a href="Cryptojacking" title="Cryptojacking">Cryptojacking</a></li>
<li><a href="Botnet" title="Botnet">Botnets</a></li>
<li><a href="Data_breach" title="Data breach">Data breach</a></li>
<li><a href="Drive-by_download" title="Drive-by download">Drive-by download</a></li>
<li><a href="Browser_Helper_Object" title="Browser Helper Object">Browser Helper Objects</a></li>
<li><a href="Computer_virus" title="Computer virus">Viruses</a></li>
<li><a href="Data_scraping" title="Data scraping">Data scraping</a></li>
<li><a href="Denial-of-service_attack" title="Denial-of-service attack">Denial-of-service attack</a></li>
<li><a href="Eavesdropping" title="Eavesdropping">Eavesdropping</a></li>
<li><a href="Email_fraud" title="Email fraud">Email fraud</a></li>
<li><a href="Email_spoofing" title="Email spoofing">Email spoofing</a></li>
<li><a href="Exploit_(computer_security)" title="Exploit (computer security)">Exploits</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialers</a></li>
<li><a href="Hacktivism" title="Hacktivism">Hacktivism</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Insecure_direct_object_reference" title="Insecure direct object reference">Insecure direct object reference</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke loggers</a></li>
<li><a href="Malware" title="Malware">Malware</a></li>
<li><a href="Payload_(computing)" title="Payload (computing)">Payload</a></li>
<li><a href="Phishing" title="Phishing">Phishing</a>
<ul><li><a href="Voice_phishing" title="Voice phishing">Voice</a></li></ul></li>
<li><a href="Polymorphic_engine" title="Polymorphic engine">Polymorphic engine</a></li>
<li><a href="Privilege_escalation" title="Privilege escalation">Privilege escalation</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkits</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Shellcode" title="Shellcode">Shellcode</a></li>
<li><a href="Spamming" title="Spamming">Spamming</a></li>
<li><a href="Social_engineering_(security)" title="Social engineering (security)">Social engineering</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Software_bug" title="Software bug">Software bugs</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horses</a></li>
<li><a href="Hardware_Trojan" title="Hardware Trojan">Hardware Trojans</a></li>
<li><a href="Remote_access_trojan" class="mw-redirect" title="Remote access trojan">Remote access trojans</a></li>
<li><a href="Vulnerability_(computer_security)" title="Vulnerability (computer security)">Vulnerability</a></li>
<li><a href="Web_shell" title="Web shell">Web shells</a></li>
<li><a href="Wiper_(malware)" title="Wiper (malware)">Wiper</a></li>
<li><a href="Computer_worm" title="Computer worm">Worms</a></li>
<li><a href="SQL_injection" title="SQL injection">SQL injection</a></li>
<li><a href="Rogue_security_software" title="Rogue security software">Rogue security software</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie</a></li></ul>
</div></td><td class="noviewer navbox-image" rowspan="3" style="width:1px;padding:0 0 0 2px"><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Defenses</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Application_security" title="Application security">Application security</a>
<ul><li><a href="Secure_coding" title="Secure coding">Secure coding</a></li>
<li>Secure by default</li>
<li><a href="Secure_by_design" title="Secure by design">Secure by design</a>
<ul><li><a href="Misuse_case" title="Misuse case">Misuse case</a></li></ul></li></ul></li>
<li><a href="Computer_access_control" title="Computer access control">Computer access control</a>
<ul><li><a href="Authentication" title="Authentication">Authentication</a>
<ul><li><a href="Multi-factor_authentication" title="Multi-factor authentication">Multi-factor authentication</a></li></ul></li>
<li><a href="Authorization" title="Authorization">Authorization</a></li></ul></li>
<li><a href="Computer_security_software" title="Computer security software">Computer security software</a>
<ul><li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Security-focused_operating_system" title="Security-focused operating system">Security-focused operating system</a></li></ul></li>
<li><a href="Data-centric_security" title="Data-centric security">Data-centric security</a></li>
<li><a href="Obfuscation_(software)" title="Obfuscation (software)">Software obfuscation</a></li>
<li><a href="Data_masking" title="Data masking">Data masking</a></li>
<li><a href="Encryption" title="Encryption">Encryption</a></li>

<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a>
<ul><li><a href="Host-based_intrusion_detection_system" title="Host-based intrusion detection system">Host-based intrusion detection system</a> (HIDS)</li>
<li><a href="Anomaly_detection" title="Anomaly detection">Anomaly detection</a></li></ul></li>
<li><a href="Information_security_management" title="Information security management">Information security management</a>
<ul><li><a href="Information_risk_management" class="mw-redirect" title="Information risk management">Information risk management</a></li>
<li><a href="Security_information_and_event_management" title="Security information and event management">Security information and event management</a> (SIEM)</li></ul></li>
<li><a href="Runtime_application_self-protection" title="Runtime application self-protection">Runtime application self-protection</a></li>
<li><a href="Site_isolation" title="Site isolation">Site isolation</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Related<br>security<br>topics</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_security" title="Computer security">Computer security</a></li>
<li><a href="Automotive_security" title="Automotive security">Automotive security</a></li>
<li><a href="Cybercrime" title="Cybercrime">Cybercrime</a>
<ul><li><a href="Cybersex_trafficking" title="Cybersex trafficking">Cybersex trafficking</a></li>
<li><a href="Computer_fraud" title="Computer fraud">Computer fraud</a></li></ul></li>
<li><a href="Cybergeddon" title="Cybergeddon">Cybergeddon</a></li>
<li><a href="Cyberterrorism" title="Cyberterrorism">Cyberterrorism</a></li>
<li><a href="Cyberwarfare" title="Cyberwarfare">Cyberwarfare</a></li>
<li><a href="Electronic_warfare" title="Electronic warfare">Electronic warfare</a></li>
<li><a href="Information_warfare" title="Information warfare">Information warfare</a></li>
<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li>
<li><a href="Copy_protection" title="Copy protection">Copy protection</a></li>
<li><a href="Digital_rights_management" title="Digital rights management">Digital rights management</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox" aria-labelledby="Firewall_software268" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Firewall_software268" style="font-size:114%;margin:0 4em"></div></th></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><a href="Application_firewall" title="Application firewall">Application firewall</a></li>
<li><a href="Context-based_access_control" title="Context-based access control">Context-based access control</a></li>
<li><a href="Personal_firewall" title="Personal firewall">Personal firewall</a></li>
<li><a href="Stateful_firewall" title="Stateful firewall">Stateful firewall</a></li>
<li><a href="Virtual_firewall" title="Virtual firewall">Virtual firewall</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux" title="Linux">Linux</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Apps</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="FireHOL" title="FireHOL">FireHOL</a></li>
<li><a href="Firestarter_(firewall)" title="Firestarter (firewall)">Firestarter</a></li>
<li><a href="Firewalld" title="Firewalld">firewalld</a></li>
<li><a href="Netfilter" title="Netfilter">Netfilter</a>
<ul><li><a href="Iptables" title="Iptables">iptables</a></li>
<li><a href="Nftables" title="Nftables">nftables</a></li></ul></li>
<li><a href="MoBlock" title="MoBlock">MoBlock</a></li>
<li><a href="Privoxy" title="Privoxy">Privoxy</a></li>
<li><a href="Shorewall" title="Shorewall">Shorewall</a></li>
<li><a href="Squid_(software)" title="Squid (software)">Squid</a></li>
<li><a href="Uncomplicated_Firewall" title="Uncomplicated Firewall">Uncomplicated Firewall</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_distribution" title="Linux distribution">Distros</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Endian_Firewall" title="Endian Firewall">Endian Firewall</a></li>
<li><a href="IPFire" title="IPFire">IPFire</a></li>
<li><a href="OpenWrt" title="OpenWrt">OpenWrt</a> (<a href="LEDE" class="mw-redirect" title="LEDE">LEDE</a>)</li>
<li><a href="SmoothWall" class="mw-redirect" title="SmoothWall">SmoothWall</a></li>
<li><a href="VyOS" title="VyOS">VyOS</a></li>
<li><a href="Zeroshell" title="Zeroshell">Zeroshell</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="BSD" class="mw-redirect" title="BSD">BSD</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Apps</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="IPFilter" title="IPFilter">IPFilter</a></li>
<li><a href="Ipfirewall" title="Ipfirewall">ipfirewall</a></li>
<li><a href="NPF_(firewall)" title="NPF (firewall)">NPF</a></li>
<li><a href="PF_(firewall)" title="PF (firewall)">PF</a>
<ul><li><a href="Pfsync" title="Pfsync">pfsync</a></li></ul></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Distros</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="OPNsense" title="OPNsense">OPNsense</a></li>
<li><a href="PfSense" title="PfSense">pfSense</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="MacOS" title="MacOS">macOS</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Little_Snitch" title="Little Snitch">Little Snitch</a></li>
<li><a href="NetBarrier_X4" title="NetBarrier X4">NetBarrier X4</a></li>
<li><a href="PeerGuardian" title="PeerGuardian">PeerGuardian</a></li>
<li><a href="Intego#VirusBarrier" title="Intego">VirusBarrier X6</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Microsoft_Windows" title="Microsoft Windows">Windows</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Commercial</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Check_Point_Integrity" title="Check Point Integrity">Check Point Integrity</a></li>
<li><a href="Kaspersky_Internet_Security" title="Kaspersky Internet Security">Kaspersky Internet Security</a></li>
<li><a href="McAfee_Personal_Firewall_Plus" class="mw-redirect" title="McAfee Personal Firewall Plus">McAfee Personal Firewall Plus</a></li>
<li><a href="Norton_360" title="Norton 360">Norton 360</a></li>
<li><a href="Symantec_Endpoint_Protection" title="Symantec Endpoint Protection">Symantec Endpoint Protection</a></li>
<li><a href="Trend_Micro_Internet_Security" title="Trend Micro Internet Security">Trend Micro Internet Security</a></li>
<li><a href="Windows_Firewall" title="Windows Firewall">Windows Firewall</a></li>
<li><a href="WinGate" title="WinGate">WinGate</a></li>
<li><a href="WinRoute" class="mw-redirect" title="WinRoute">WinRoute</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Freemium" title="Freemium">Freemium</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Comodo_Internet_Security" title="Comodo Internet Security">Comodo Internet Security</a></li>
<li><a href="ZoneAlarm" title="ZoneAlarm">ZoneAlarm</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Open-source</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="PeerBlock" title="PeerBlock">PeerBlock</a></li>
<li><a href="PeerGuardian" title="PeerGuardian">PeerGuardian</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">discontinued</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Microsoft_Forefront_Threat_Management_Gateway" title="Microsoft Forefront Threat Management Gateway">Microsoft Forefront Threat Management Gateway</a></li>
<li><a href="Norton_Internet_Security" title="Norton Internet Security">Norton Internet Security</a></li>
<li><a href="Norton_Personal_Firewall" title="Norton Personal Firewall">Norton Personal Firewall</a></li>
<li><a href="Outpost_Firewall_Pro" title="Outpost Firewall Pro">Outpost Firewall Pro</a></li>
<li><a href="Windows_Live_OneCare" title="Windows Live OneCare">Windows Live OneCare</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><a href="List_of_router_or_firewall_distributions" class="mw-redirect" title="List of router or firewall distributions">List of router or firewall distributions</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox" aria-labelledby="Malware_topics109" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Malware_topics109" style="font-size:114%;margin:0 4em"><a href="Malware" title="Malware">Malware</a> topics</div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Infectious malware</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Comparison_of_computer_viruses" title="Comparison of computer viruses">Comparison of computer viruses</a></li>
<li><a href="Computer_virus" title="Computer virus">Computer virus</a></li>
<li><a href="Computer_worm" title="Computer worm">Computer worm</a></li>
<li><a href="List_of_computer_worms" title="List of computer worms">List of computer worms</a></li>
<li><a href="Timeline_of_computer_viruses_and_worms" title="Timeline of computer viruses and worms">Timeline of computer viruses and worms</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Concealment</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoor</a></li>
<li><a href="Clickjacking" title="Clickjacking">Clickjacking</a></li>
<li><a href="Man-in-the-browser" title="Man-in-the-browser">Man-in-the-browser</a></li>
<li><a href="Man-in-the-middle_attack" title="Man-in-the-middle attack">Man-in-the-middle</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkit</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie computer</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Malware for profit</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Botnet" title="Botnet">Botnet</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Fleeceware" title="Fleeceware">Fleeceware</a></li>
<li><a href="Form_grabbing" title="Form grabbing">Form grabbing</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialer</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke logging</a></li>
<li><a href="Internet_bot#Malicious_purposes" title="Internet bot">Malbot</a></li>
<li><a href="Privacy-invasive_software" class="mw-redirect" title="Privacy-invasive software">Privacy-invasive software</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Rogue_security_software" title="Rogue security software">Rogue security software</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Web_threat" title="Web threat">Web threats</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">By operating system</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>Android malware</li>
<li>Classic Mac OS viruses</li>
<li>iOS malware</li>
<li><a href="Linux_malware" title="Linux malware">Linux malware</a></li>
<li>MacOS malware</li>
<li><a href="Macro_virus" title="Macro virus">Macro virus</a></li>
<li><a href="Mobile_malware" title="Mobile malware">Mobile malware</a></li>
<li><a href="Palm_OS_viruses" title="Palm OS viruses">Palm OS viruses</a></li>
<li><a href="HyperCard_viruses" class="mw-redirect" title="HyperCard viruses">HyperCard viruses</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Protection</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anti-keylogger" title="Anti-keylogger">Anti-keylogger</a></li>
<li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Browser_security" title="Browser security">Browser security</a></li>
<li><a href="Data_loss_prevention_software" title="Data loss prevention software">Data loss prevention software</a></li>
<li><a href="Defensive_computing" title="Defensive computing">Defensive computing</a></li>

<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Countermeasures</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_and_network_surveillance" title="Computer and network surveillance">Computer and network surveillance</a></li>
<li><a href="Honeypot_(computing)" title="Honeypot (computing)">Honeypot</a></li>
<li><a href="Operation%3A_Bot_Roast" title="Operation: Bot Roast">Operation: Bot Roast</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1038841319">
/* start https://en.wikipedia.org/ */


.mw-parser-output .tooltip-dotted{border-bottom:1px dotted;cursor:help}


/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox authority-control" aria-labelledby="Authority_control_databases_frameless&amp;#124;text-top&amp;#124;10px&amp;#124;alt=Edit_this_at_Wikidata&amp;#124;link=https&amp;#58;//www.wikidata.org/wiki/Q80998#identifiers&amp;#124;class=noprint&amp;#124;Edit_this_at_Wikidata1002" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Authority_control_databases_frameless&amp;#124;text-top&amp;#124;10px&amp;#124;alt=Edit_this_at_Wikidata&amp;#124;link=https&amp;#58;//www.wikidata.org/wiki/Q80998#identifiers&amp;#124;class=noprint&amp;#124;Edit_this_at_Wikidata1002" style="font-size:114%;margin:0 4em">Authority control databases </div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">National</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"><ul><li><span class="uid"><a rel="nofollow" class="external text" href="https://d-nb.info/gnd/4386332-2">Germany</a></span></li><li><span class="uid"><a rel="nofollow" class="external text" href="https://id.loc.gov/authorities/sh00006011">United States</a></span></li><li><span class="uid"><span class="rt-commentedText tooltip tooltip-dotted" title="firewally"><a rel="nofollow" class="external text" href="https://aleph.nkp.cz/F/?func=find-c&amp;local_base=aut&amp;ccl_term=ica=ph136554&amp;CON_LNG=ENG">Czech Republic</a></span></span></li><li><span class="uid"><a rel="nofollow" class="external text" href="https://www.nli.org.il/en/authorities/987007291711605171">Israel</a></span></li></ul></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Other</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em"><ul><li><span class="uid"><a rel="nofollow" class="external text" href="https://lux.collections.yale.edu/view/concept/07bd37c1-8c42-4e3d-8f42-afdcdf8b1ac5">Yale LUX</a></span></li></ul></div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-14" href="https://en.wikipedia.org/wiki/?title=Firewall_(computing)&amp;oldid=1295521940">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>