IT Glossary / Firewall
IT Glossary · Network SecurityFirewall
The security barrier between your internal network and the internet - monitoring and controlling every packet of traffic based on rules your IT team defines.
A firewall is a security device or software that monitors and controls incoming and outgoing network traffic based on predetermined rules. It acts as a barrier between your trusted internal network and untrusted networks like the internet.
Your first line of defence - and your last if nothing else is in place
Every Australian business with an internet connection needs a firewall. It's not optional, and the Windows built-in version isn't enough for a business network.
A firewall works by applying a set of rules to every packet of data attempting to enter or leave your network. Rules can allow, deny, or log traffic based on source address, destination, port, protocol, application, or any combination of these attributes. Traffic that matches no allow rule is blocked by default.
A properly configured Next-Generation Firewall (NGFW) is a required control under the ACSC's Essential Eight. Without one, achieving any meaningful maturity level is not possible regardless of what other security tools you have in place.
For Australian SMBs, the most common gap is not the absence of a firewall entirely - it's a firewall that was installed years ago, never reviewed, and is now running outdated firmware with rules that no longer reflect the business. A firewall is only as good as its last audit.
Modern Next-Generation Firewalls go beyond basic packet filtering. They inspect the content of traffic (deep packet inspection), identify applications regardless of port, integrate with threat intelligence feeds to block known malicious addresses in real time, and generate logs that feed into your security monitoring. A basic firewall from 2015 does none of this.
What a business-grade firewall actually does
A modern firewall is not just a traffic filter - it's an active security control that monitors, logs and responds to threats in real time.
Traffic Monitoring & Rule Enforcement
Every connection attempt - inbound and outbound - is evaluated against a rule set. Permitted traffic passes. Everything else is blocked and logged. Rules are maintained by your IT team and updated as the business changes - new applications, new sites, new risks.
Deep Packet Inspection (DPI)
Next-Generation Firewalls inspect the content of encrypted and unencrypted traffic, not just its header. This identifies malicious payloads, command-and-control traffic, and data exfiltration attempts that basic port-based filtering would miss entirely.
Application Awareness
Modern firewalls identify applications regardless of port - so you can allow Microsoft Teams but block peer-to-peer file sharing, even if both use port 443. This level of control is impossible with traditional firewalls that only understand ports and protocols.
Threat Intelligence Integration
NGFWs connect to live threat intelligence feeds and automatically block traffic to and from known malicious IP addresses, domains and URLs - updated in real time. Your firewall becomes aware of new threats within hours of them being identified globally.
Logging & Security Monitoring
Every connection is logged. Blocked connections are flagged. Unusual patterns - a device suddenly scanning internal IP ranges, outbound data transfers at 3am - are detected and can trigger alerts to your IT team or security operations platform.
Hardware vs Software vs Next-Gen
| Type | What it protects | Managed by | Suitable for | Limitation |
|---|---|---|---|---|
| Hardware Network Firewall | The entire network - all devices behind it | IT team / MSP centrally | Any business with a physical or hybrid network | Doesn't follow devices off the network (remote workers) |
| Software Host Firewall | The individual device it's installed on | Local device or endpoint management | Supplementary layer for laptops and remote devices | Doesn't protect the wider network; limited visibility |
| Next-Gen NGFW | Network + application layer + content inspection | IT team / MSP with security dashboard | Businesses with compliance requirements or sensitive data | Higher cost; requires expertise to configure correctly |
Most Australian businesses should use a hardware or NGFW at the network perimeter alongside host-based firewall controls on individual devices, particularly for staff working remotely.
Firewall - Frequently Asked Questions
What is a firewall?
A firewall is a security device or software that monitors and controls incoming and outgoing network traffic based on defined rules, acting as a barrier between your trusted internal network and untrusted networks like the internet. It blocks traffic that doesn't match an explicit allow rule.
What is the difference between a hardware and software firewall?
A hardware firewall is a physical device that protects your whole network at the perimeter - all traffic in and out passes through it. A software firewall runs on an individual device and protects just that machine. Most businesses use both layers together for defence in depth.
Is the firewall built into Windows enough?
The Windows Defender Firewall is a useful baseline for a single device, but it doesn't protect the wider network, can't see traffic from other devices, and has no centralised management, logging or threat intelligence. Businesses need a dedicated network firewall to meet compliance requirements and protect all users.
Does a firewall protect against ransomware?
A firewall is one layer of ransomware protection - it can block known malicious connections and prevent lateral movement across the network after an infection. But ransomware typically enters via email or web browsing, which firewalls alone can't stop. Defence in depth (endpoint protection, email filtering, backups) is required alongside a firewall.
How often should a firewall be reviewed?
Firewall rules should be audited at least annually, and any time the business changes significantly - new office locations, new cloud services, staff changes. Firmware and software should be kept current. Many breaches exploit known vulnerabilities in outdated firewall firmware that was never updated after initial install.
What is a Next-Generation Firewall (NGFW)?
An NGFW combines traditional packet filtering with deep packet inspection, application identification, SSL decryption, intrusion prevention, and threat intelligence feeds. It sees inside encrypted traffic and identifies applications regardless of port - providing significantly more protection than a traditional firewall and meeting modern compliance requirements.
Not sure if your firewall is actually doing its job?
Our network assessment reviews your firewall configuration, firmware version, rule set and logging - and tells you plainly what's working, what's outdated, and what needs fixing.
Book a Network Assessment Call 1300 425 548