A network security control that filters traffic between networks based on defined rules, allowing legitimate connections and blocking unwanted ones.
A firewall enforces a boundary between zones of different trust, for example between the internet and an internal network. It inspects traffic against a rule set and permits or denies it. Modern next-generation firewalls also inspect application traffic and integrate threat intelligence.
Firewalls are a foundational preventive control, but layered defenses are still needed because not all threats arrive over the network perimeter.
Related frameworks