What is a firewall? Rules, ports and network access
A firewall allows or blocks network traffic according to rules. It can run on a computer, a home router or at a cloud network boundary. Rules control access to connections; they do not automatically make an allowed application secure.
How firewall rules work
A rule can consider the direction of a connection, addresses, protocol, port and sometimes the application. A home router typically limits unsolicited incoming traffic, while an operating-system firewall controls traffic reaching the device itself. State-aware firewalls can permit replies to established outbound connections without opening every inbound port.
Traffic may pass several layers. A cloud security group can allow a port while the host firewall blocks it. A local allow rule may also be ineffective when a router does not forward the port or the Internet provider uses carrier-grade NAT. Identify each layer before making broad changes.
Why a service is unreachable
First check that the application is running and listening on the expected protocol, port and network address. A service bound only to loopback is available locally but not externally. Then inspect the host rule, router forwarding and provider restrictions. An external port test can show reachability from its vantage point but cannot identify the only cause of failure.
Distinguish a refused connection, a timeout and an application-level error. These suggest different points of failure, although filtering can obscure them. Test from a genuinely separate network; some routers handle connections to their own public address differently from outside traffic.
A safer rule change
Allow only the access needed by the service, preferably from limited source addresses where practical. Keep the service updated and require appropriate authentication. Document why a rule exists and remove it when the service is retired. Blocking every outbound connection can break updates or DNS, so understand dependencies before applying a rule.
A firewall does not prevent phishing, unsafe downloads or exploitation through an allowed service. Use it with updates, backups and account security. After a change, verify both the required connection and the absence of unintended exposure.
For IPv6, verify the actual interface address and firewall policy rather than assuming IPv4 NAT rules apply. An application can listen on one address family while a client tries the other.
