What a Firewall Does, and What It Does Not
Short answer
A firewall decides which network connections are allowed in or out, based on port, program and direction. It blocks unsolicited inbound connections, which is genuinely valuable. It cannot stop phishing, a malicious download, or a compromised website, because you requested those connections yourself.
On this page
A firewall is a filter for network connections. It looks at traffic trying to enter or leave a device and decides, by rule, whether to allow it. The rules consider the port, the protocol, the direction, and on a modern operating system, which program is involved.
That is the whole mechanism. It is useful, it is already running on every device you own, and it is routinely described in security advertising as though it assesses intent. It does not. A firewall has no opinion about whether a file is malicious; it only knows whether a connection matches a rule.
What it blocks well
Unsolicited inbound connections. Something on the internet attempting to reach a service on your machine that you did not expose deliberately. This is the firewall’s core job and it does it reliably.
That matters more than it sounds. Operating systems run background network services — file sharing, printer discovery, remote assistance — and historically, flaws in those services allowed remote compromise with no user action at all. Several of the most damaging worms spread exactly that way. A machine with no inbound ports open is simply not reachable by that class of attack.
Public network isolation. When Windows asks whether a network is public or private, it is choosing a firewall profile. Public blocks local discovery and sharing, which is correct for a café or hotel and is why answering that prompt accurately is worth two seconds of thought.
Outbound control, in a limited way. Windows Defender Firewall can block specific programs from reaching the network. Useful for pinning an application offline. Not a general defence, for reasons below.
What it does not do
This is the part the marketing omits.
| Threat | Firewall helps? | Why |
|---|---|---|
| Phishing email | No | You typed the credential on a site you visited |
| Malicious download | No | You requested the connection |
| Compromised website | No | Ordinary outbound web traffic |
| Browser extension stealing data | No | Traffic belongs to the browser |
| Ransomware encrypting files | No | No network step required |
| Remote exploit of an open port | Yes | This is exactly its job |
| Malware reaching its operator | Partly | Only if a rule catches it |
The pattern is clear. A firewall filters connections, so it helps against attacks that need an inbound connection. The threats that actually reach ordinary people arrive through connections you initiated — a web page you opened, a file you downloaded, a link you clicked — and those look identical to legitimate browsing.
The last row deserves nuance. A firewall can block malware from contacting its operator, which is a real containment benefit. In practice, most malware uses ordinary outbound HTTPS on port 443, the same as every website, so a rule targeting it would block normal browsing too. Outbound filtering works well in corporate networks with dedicated staff and poorly on a home PC.
Why outbound prompts are mostly noise
Third-party firewalls sell themselves on asking whether each program may access the internet. It sounds like control and usually is not.
The prompts arrive constantly, name executables rather than purposes
(svchost.exe wants to connect), and give no information on which to base a
decision. Within a week nearly everyone clicks Allow reflexively, which is the
same security posture as having no prompts at all but with more interruptions.
Worse, malware sophisticated enough to matter typically operates through a process you have already permitted — the browser being the obvious candidate.
Checking yours is on
Windows. Windows Security → Firewall & network protection. Three profiles: Domain, Private, Public. All should say “Firewall is on”. If one is off, something turned it off — some malware does this, and so do badly written games and VPN clients.
To allow a specific program: Windows Security → Firewall & network protection → Allow an app through firewall. Allow it on the narrowest profile that solves the problem, which is usually Private only. Never turn the firewall off as a permanent answer to one application’s problem.
macOS. System Settings → Network → Firewall. On macOS it is off by default, which surprises people. That is a defensible choice, because macOS does not expose inbound services by default, so there is little to protect. Turning it on is still reasonable, particularly on a laptop that joins networks you do not control, and it costs nothing.
Your router. No action needed. Home routers use network address translation, which means inbound connections have no internal destination unless you forwarded a port deliberately. The firewall behaviour is a consequence of the addressing.
Worth checking, though: that UPnP is not opening ports for devices without your knowledge, and that remote administration is off. Both live in the router’s admin pages, and both are discussed in how devices end up in a botnet.
Port forwarding is the hole you make yourself
Setting up a game server, a security camera or remote access means forwarding a port, which creates exactly the inbound path the firewall exists to prevent. Sometimes necessary. Always a deliberate decision.
If you do it: forward one specific port, not a range. Make sure the device behind it has a changed password and current firmware. Remove the rule when you no longer need it. A forgotten forward to a camera with default credentials is one of the more reliable routes into a home network.
What to rely on instead
A firewall is one layer and not the one doing most of the work for a typical person.
- Keep the operating system and browser updated. Patches close the flaws that inbound attacks need.
- Antivirus for files. Microsoft Defender handles this on Windows; the comparison with paid options is in whether free antivirus is enough.
- A password manager and two-factor authentication for credentials, which is where real losses happen.
- Backups for ransomware, since nothing else works after the fact.
- Your own judgement on links and downloads, because the firewall has no view on those at all.
Realistic expectations
Your firewall is almost certainly already on and already doing its job, and the correct amount of attention to pay it is very little. Confirm it is enabled, answer the public-or-private prompt honestly, avoid leaving ports forwarded to things you have forgotten about, and move on.
The honest limitation is that firewalls defend against a shape of attack that is no longer how most people get into trouble. The threats that reach you now arrive through connections you opened yourself, wrapped in ordinary encrypted web traffic, and no rule about ports can distinguish them from everything else you do all day.