A firewall applies rules to control network traffic: it permits or blocks communications according to a security policy. Firewalls have developed from basic packet filters into systems that can track connections and, in some cases, inspect application protocols. They remain useful in modern networks—including zero-trust and cloud architectures—but work as one part of a broader security design, not as a substitute for every other control.
What is a firewall?
A firewall is a device or software function that controls traffic between networks or hosts according to a defined policy. NIST’s glossary describes a firewall as a gateway that limits access between networks in accordance with local security policy. The key idea is enforcement: a firewall evaluates communications against rules and allows or denies them.
That makes a firewall one security control, not a catch-all name for antivirus, identity management, intrusion detection, or every other protective measure. Depending on its deployment, it may protect a network boundary, separate internal network segments, or run on an individual host.
How does a firewall work?
A firewall compares traffic it can observe with its rules. Those rules can specify which communications are allowed, such as traffic between particular addresses or services, and which should be blocked. The firewall applies the matching policy as packets pass through it or reach a protected host.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Its decisions depend on both the rule design and the information available for inspection. A basic filter can use packet fields; more capable systems may track connections or examine protocol behavior. A firewall cannot reliably make decisions from details it cannot see.
How firewalls evolved
The sources support a progression in filtering capability, rather than a definitive account of a first inventor or a precise, generation-by-generation invention timeline. NIST’s 2009 firewall guide and IETF guidance distinguish packet filtering, stateful inspection, and more application-aware approaches. That is a useful way to understand the technology’s development without assigning unsupported dates or inventors.
Packet rules
Early and basic filtering approaches make decisions using packet information and configured rules. This is a direct way to enforce traffic policy, but each packet is evaluated without the context of a tracked connection.
Rank #2
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Connection awareness
Stateful inspection adds a record of active connections. Instead of treating every packet in isolation, the firewall checks whether traffic fits the expected state of a connection. NIST describes state information that can include source and destination IP addresses, port numbers, and connection state.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Protocol and application context
Some firewall systems go beyond packet fields and connection state to inspect protocol behavior or other application-level context. This can support more informed rules, but the level of inspection varies by system and depends on what traffic is visible to it.
What is the difference between a packet-filtering firewall and a stateful firewall?
| Approach | What it considers | Practical distinction |
|---|---|---|
| Packet filtering | Packet fields compared with configured rules | Each packet is assessed on its own; the filter does not track connection state. |
| Stateful inspection | Packet information plus records of active connections and their expected state | The firewall can distinguish traffic that belongs to an established connection from traffic that does not fit that connection’s state. |
Both approaches enforce policy, but stateful inspection has more context for its decisions. Neither label alone says how well a firewall is configured or whether its rules meet a network’s needs.
Rank #3
- Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
- 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
- DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
- HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
- Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm
Can a firewall inspect application traffic?
Some firewalls can examine protocol behavior or application-related information, but not every firewall understands every application or inspects all content. Inspection is limited by the firewall’s capabilities and by what is exposed to it.
Encryption can hide upper-layer details from an intermediary. As RFC 7754 explains, filtering systems may have less visibility into encrypted traffic, which limits what they can infer from its contents. A firewall should therefore be understood as making decisions from available information—not as automatically seeing inside every encrypted communication.
Recommended Free Tools
How firewalls support network segmentation
Segmentation divides an environment into areas with controlled communications between them. Firewalls can enforce those boundaries, helping restrict which systems or network segments may communicate. CISA’s communications infrastructure hardening guidance identifies firewalls alongside router access control lists (ACLs), stateful packet inspection, and demilitarized zones (DMZs) as mechanisms used in segmentation.
Rank #4
- BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
- COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
- POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
- COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
- FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.
The appropriate mechanism depends on the network and its policy. A firewall can be one layer in a design that also uses other infrastructure controls; its presence alone does not guarantee that segments are separated effectively.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why firewall policy and management matter
A firewall is only as useful as the policy it enforces and the way that policy is maintained. NIST’s firewall guidance treats selection, configuration, testing, deployment, and ongoing management as parts of firewall practice—not optional details after installation.
Policy must balance two needs: block communications that should not be allowed, while permitting legitimate traffic that services require. Rules that are too restrictive can interfere with standards-compliant network behavior. RFC 2979 discusses this interoperability problem, including cases in which blocking traffic can disrupt legitimate network functions.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
- Entry-Level Privacy Gateway: Designed for users who want simple online privacy protection at an affordable level—ideal for basic home networking and daily internet use.
- Secure Browsing for Everyday Needs: Perfect for email, social media, online shopping, and standard streaming—protecting your connection while keeping setup and operation easy.
- Lightweight Protection Against Common Online Threats: Helps reduce exposure to unwanted ads, trackers, and risky websites, improving online safety for your household.
- Simple Setup, No Technical Skills Required: Plug it in, follow the quick steps, and start using—an excellent choice for beginners who don’t want complicated network configurations.
- Decentralized VPN (DPN) Included – No Monthly Payments: Get built-in decentralized VPN access with lifetime free usage, helping you stay private without paying recurring subscription fees
- Define which communications should be allowed and which should be denied.
- Check rules against the legitimate requirements of the applications and services involved.
- Test changes and observe their effects before relying on them in production.
- Manage rules over time as systems, services, and network boundaries change.
Are firewalls still useful with zero trust and cloud computing?
Yes. Zero trust and cloud-oriented architectures change where policy may be enforced; they do not make traffic policy irrelevant. A NIST Zero Trust Architecture project overview presents next-generation firewalls as possible policy enforcement points in physical, virtual, containerized, and cloud-delivered forms. This is an example of firewall capabilities being deployed beyond a single perimeter appliance, not a claim that every zero-trust architecture uses the same design.
The deployment role matters as much as the device form. A firewall can enforce a boundary between networks or hosts, or serve as a distributed enforcement point in an architecture. Zero trust is not simply a replacement for firewalls, and a firewall by itself does not provide a complete zero-trust architecture.
For a general explanation of firewall technologies and policy, see NIST’s SP 800-41 Rev. 1. The standards references also include RFC 2979 on firewall behavior and interoperability and RFC 7754 on filtering and visibility constraints.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

