ADAM PULSE Knowledge Base
Cybersecurity · Firewalls · Defense in Depth

Does a firewall stop hackers?

The short answer: A properly configured firewall is one of the most important defenses between your business network and untrusted networks such as the internet. It can block unauthorized connections, restrict access to services, segment networks, log activity, and enforce security policies. But a firewall cannot stop every cyberattack.

A firewall cannot protect your business from every stolen password.

It cannot guarantee that an employee will never click a malicious link.

It cannot automatically fix vulnerable software.

It cannot protect an account that has been legitimately authenticated with stolen credentials.

And a firewall that is poorly configured can unintentionally allow exactly the traffic you expected it to block.

The right way to think about a firewall is not:

“We have a firewall, so we are secure.”

It is:

“Our firewall is an important layer in a larger cybersecurity strategy.”

That distinction matters.

What Is a Firewall?

A firewall is a security system that controls network traffic according to defined rules.

It helps determine which communications should be allowed and which should be blocked.

The National Institute of Standards and Technology, or NIST, describes firewalls as technologies that control the flow of network traffic between networks or systems with different security postures.

For a business, one of the most obvious examples is the boundary between:

Your internal network

and

The public internet.

The firewall sits between those environments and evaluates traffic according to configured security policies.

But modern firewalls can do much more than simply allow or block a connection.

Depending on the firewall and services enabled, capabilities may include:

The exact capabilities depend on the technology, licensing, configuration, and environment.

What Does a Firewall Actually Do?

At its most basic level, a firewall decides whether network communications should be permitted.

Imagine your business network as a building.

Without any controls, people could potentially approach every door.

A firewall acts somewhat like a combination of:

a gate

a security guard

an access control system

and

a visitor log.

The firewall evaluates who or what is attempting to communicate and applies rules.

For example:

Allow this traffic.

Block that traffic.

Only permit this application.

Only allow connections from these locations.

Allow employees to connect through the VPN.

Prevent outside systems from directly reaching this internal server.

That is enormously valuable.

But even the best security guard cannot protect a building if someone has been issued a valid access badge that was stolen.

That is where other cybersecurity controls become important.

Does a Firewall Stop Hackers?

A firewall can stop many unauthorized network connections and can make attacking your network considerably more difficult.

But no responsible cybersecurity professional should tell a business:

“Install this firewall and hackers cannot get in.”

Cybersecurity does not work that way.

Attackers have many possible paths.

Some attacks attempt to pass through the network perimeter.

Others attempt to convince an authorized user to provide access.

Others target cloud accounts.

Others exploit vulnerable applications.

Others abuse legitimate remote access.

Others compromise third party vendors.

Others begin with malicious email.

Others target devices that are already permitted to communicate.

The firewall is an important security layer.

It is not the entire security program.

What Can a Firewall Protect Against?

Properly configured firewalls can help protect businesses in several important ways.

1. Blocking Unwanted Incoming Connections

A business generally should not expose every computer and service directly to the internet.

A firewall helps restrict which external communications are allowed to reach internal systems.

If a connection does not meet the organization's rules, the firewall can block it.

That significantly reduces unnecessary exposure.

2. Limiting Which Services Are Accessible

Your company may operate dozens or hundreds of network services internally.

Most do not need to be reachable from the public internet.

A firewall can allow only the services that have a legitimate business requirement.

This follows an important security principle:

If something does not need to be exposed, do not expose it.

Reducing unnecessary exposure reduces the attack surface.

3. Restricting Remote Access

Businesses frequently need to provide remote access for:

That access should not necessarily provide unrestricted connectivity from anywhere on the internet.

Firewalls can help enforce policies around remote access.

Combined with secure remote access technologies and multifactor authentication, this creates stronger protection.

CISA specifically recommends requiring multifactor authentication for remote access and privileged or administrative access.

4. Segmenting Networks

A firewall can also separate different parts of a business network.

This concept is called network segmentation.

Instead of placing every device into one enormous network, organizations can create logical boundaries between different types of systems.

For example:

Employee computers

Servers

Security cameras

Guest WiFi

Voice systems

Point of sale systems

Building controls

Administrative systems

Internet of Things devices

These systems do not necessarily need unrestricted access to one another.

CISA recommends strong network segmentation as part of a broader defense in depth approach and specifically discusses using firewalls, access controls, and separate network segments to isolate groups of systems.

Why Is Network Segmentation Important?

Imagine a hotel.

A guest's room key allows access to:

their room

the elevator

common areas

It does not automatically open:

every guest room

the accounting office

the kitchen

the security room

the manager's office

the server room

That is segmentation.

Access is limited according to need.

Your network should follow a similar philosophy.

A security camera should not necessarily have the same access as the Chief Financial Officer's computer.

A guest using WiFi should not automatically be able to reach business servers.

A printer should not necessarily communicate with every device in the organization.

A compromise becomes more dangerous when the attacker can freely move from one system to another.

Segmentation creates boundaries.

Can Hackers Get Through a Firewall?

Yes, under certain circumstances.

That does not mean the firewall has failed as a technology.

It means firewalls operate according to rules and exist within a much larger technology environment.

There are several ways an attacker may effectively bypass or move beyond the protection provided by a firewall.

1. The Firewall Allows the Traffic

This is one of the most important concepts to understand.

A firewall is designed to allow legitimate communications.

If your company operates a website, people must reach it.

If employees use a VPN, VPN traffic must be allowed.

If you use cloud applications, devices must communicate with those platforms.

If a vendor remotely supports equipment, some form of authorized communication may exist.

Attackers frequently attempt to take advantage of services that businesses intentionally expose.

The firewall may therefore be working exactly as configured.

The problem may exist behind the permitted connection.

2. Someone Creates an Unsafe Firewall Rule

Firewalls follow rules.

Those rules are created by people.

People make mistakes.

Imagine someone says:

“The vendor cannot reach the server. Open access temporarily.”

A rule is created.

The problem is fixed.

The project ends.

Six months later, the rule still exists.

Nobody remembers why.

Now something that was supposed to be temporary has become part of the permanent attack surface.

This is why firewall reviews matter.

What Is a Firewall Rule?

A firewall rule defines what traffic should be allowed or denied.

Rules can consider factors such as:

Rules can be extremely specific.

Or dangerously broad.

For example:

Allow one authorized source to reach one necessary service

is very different from:

Allow everyone on the internet to reach everything.

The quality of the firewall's protection depends heavily on the quality of its policy.

Why Firewall Configuration Matters So Much

The Federal Trade Commission makes an important point in its business security guidance:

The protection a firewall provides is only as effective as the access controls configured within it.

That means businesses should not simply ask:

“Do we own a firewall?”

They should ask:

“Is our firewall configured correctly?”

And:

“When was that configuration last reviewed?”

Those are very different questions.

3. The Firewall Itself May Have a Vulnerability

A firewall is not magic.

It is a computer.

It runs:

And software can contain vulnerabilities.

That means the security device protecting the network must itself be protected.

Firewalls require:

Updates.

Patches.

Secure administrative access.

Strong credentials.

Configuration review.

Monitoring.

Backups.

Lifecycle management.

An unsupported firewall running old software may create risk rather than eliminate it.

Do Firewalls Need Software and Firmware Updates?

Yes.

This is critical.

Security vulnerabilities can be discovered in networking equipment just as they are discovered in:

The FTC recommends keeping router software current, while NIST and CISA repeatedly emphasize patching vulnerable systems as part of cybersecurity risk management.

Security infrastructure should not be excluded from patch management merely because it is security infrastructure.

In fact, internet facing security appliances often deserve particularly careful attention.

4. Stolen Credentials Can Give an Attacker Legitimate Access

Suppose an employee is authorized to use your VPN.

Their username and password are stolen.

The attacker signs in.

From the firewall's perspective, the connection may initially look legitimate.

The credentials are valid.

This is one reason password security alone is not enough.

Multifactor authentication provides an additional layer.

CISA recommends requiring MFA wherever possible and specifically prioritizes remote and administrative access.

The principle is straightforward:

Even if an attacker obtains the password, they should still face another barrier.

Does MFA Replace a Firewall?

No.

And a firewall does not replace MFA.

They solve different problems.

A firewall helps control network access and traffic.

MFA helps control identity and authentication.

Endpoint protection helps protect devices.

Email security helps protect communications.

Vulnerability management helps identify known weaknesses.

Backups help support recovery.

Monitoring helps improve visibility and detection.

Each control contributes something different.

That is the essence of layered cybersecurity.

5. Phishing Can Bypass the Traditional Perimeter

Imagine an attacker sends a convincing email to an employee.

The employee clicks a link.

They enter their Microsoft 365 credentials into a fake login page.

The attacker now has the credentials.

No attacker had to smash through the firewall.

The employee's web browser was already authorized to communicate with the internet.

This illustrates why cybersecurity cannot focus entirely on the traditional network perimeter.

Modern businesses operate across:

The boundary has changed.

Identity, devices, applications, and data matter alongside the firewall.

6. Malware May Travel Through Allowed Traffic

A firewall needs to permit legitimate business activity.

Employees need web access.

Applications need internet connectivity.

Email systems need to communicate.

Cloud services need to function.

An attacker may attempt to hide malicious activity within communications that would otherwise appear legitimate.

More advanced security technologies can inspect traffic and identify suspicious patterns.

But no inspection technology is perfect.

That is why endpoint security and behavioral monitoring remain important.

7. A Trusted Vendor Can Become a Path Into the Network

Businesses routinely give vendors some form of access.

Examples include:

That access can be necessary.

But it should be controlled.

The FTC recommends incorporating security requirements into vendor relationships and limiting vendor access according to business need.

Ask:

Does this vendor need access?

To what?

From where?

For how long?

Is MFA required?

Is the activity logged?

Does the account still need to exist?

Vendor access should be intentional rather than permanent by default.

8. Cloud Applications May Sit Outside Your Firewall

This is another major change in modern networking.

Years ago, much of a company's information may have existed inside the office.

Today, businesses rely on services such as:

An attacker targeting a cloud identity may never need to communicate directly with the company's office firewall.

That does not make the firewall less important.

It means cybersecurity now requires protection across multiple boundaries.

Does a Firewall Protect Microsoft 365?

A traditional office firewall can control and inspect some traffic between local users and internet services.

But Microsoft 365 accounts are cloud identities.

Protecting them also depends on controls such as:

An attacker who steals an employee's cloud credentials may be able to access cloud resources from somewhere entirely outside the company's physical network.

This is why the modern security perimeter includes identity.

Does a Firewall Protect Against Ransomware?

A firewall can contribute significantly to ransomware defense.

It can:

But a firewall by itself cannot guarantee ransomware prevention.

Ransomware can enter through:

CISA's ransomware guidance recommends multiple defensive measures, including network segmentation, secure remote access, monitoring, vulnerability management, and other safeguards.

This is a defense in depth approach.

What Is Defense in Depth?

Defense in depth means relying on multiple security layers rather than trusting one control to stop everything.

Imagine protecting an important building.

You might use:

Exterior lighting

Locks

Cameras

An alarm

Access cards

Security guards

Interior doors

A safe

Visitor records

Emergency procedures

No responsible security plan would say:

“We installed a front door lock, so we no longer need anything else.”

Cybersecurity works the same way.

The firewall is an important lock.

But it is not the building's entire security system.

What Security Layers Should a Small Business Consider?

The exact answer depends on the business, but important layers commonly include:

Firewall Security

Control network access and reduce unnecessary exposure.

Multifactor Authentication

Add protection when passwords are compromised.

Endpoint Protection

Protect computers and servers against malicious activity.

Patch Management

Correct known software vulnerabilities.

Email Security

Reduce phishing and malicious message risks.

Backups

Support recovery after destructive events.

Network Segmentation

Limit unnecessary communication between systems.

Secure Remote Access

Protect VPN, remote administration, and support connectivity.

Vulnerability Management

Identify and prioritize security weaknesses.

Monitoring and Logging

Improve visibility into important events and changes.

Employee Training

Help people recognize phishing, social engineering, and suspicious activity.

Incident Response

Establish what happens when security controls detect a problem.

No single layer makes every other layer unnecessary.

Should Every Business Have a Firewall?

Businesses operating internal networks should carefully consider appropriate firewall protection as part of their cybersecurity architecture.

The specific technology depends on the environment.

A five employee office has different requirements from:

But the security principle remains similar:

Control what is allowed to communicate with your network.

Is the Router From My Internet Provider a Firewall?

Many routers and internet gateways include some firewall capabilities.

But the capabilities can vary substantially.

A basic gateway may provide:

A business class security appliance may provide much more advanced features such as:

The right solution should be based on the organization's risk, applications, network design, compliance requirements, and operational needs.

What Is a Next Generation Firewall?

The term next generation firewall, often abbreviated NGFW, generally refers to firewall technology that combines traditional network controls with more advanced security capabilities.

Depending on the product, this can include:

The terminology can vary between manufacturers.

Businesses should focus less on whether a product carries a particular marketing label and more on:

What security capabilities do we actually need?

Which capabilities are enabled?

Who manages them?

Who monitors them?

Are they properly configured?

What Is Intrusion Prevention on a Firewall?

An Intrusion Prevention System, or IPS, analyzes activity looking for patterns associated with known malicious behavior or exploitation.

When configured to prevent activity, it may automatically block certain threats.

This can add a powerful layer beyond traditional port based firewall rules.

But IPS requires proper management.

Security signatures need updates.

Policies need tuning.

False positives need investigation.

Blocked activity needs logging.

A security feature being included in a product does not necessarily mean it is enabled, configured correctly, licensed, monitored, or maintained.

That distinction is extremely important.

“Our Firewall Has That Feature” Does Not Mean the Feature Is Protecting You

Modern security appliances can contain dozens of capabilities.

But businesses should ask:

Is the feature enabled?

Is the subscription active?

Are signatures current?

Is the policy configured?

Are logs being collected?

Are alerts going somewhere?

Does someone review them?

A feature that exists but has never been configured provides very different protection from a properly deployed and monitored service.

This is an important cybersecurity lesson beyond firewalls.

Capability is not the same as implementation.

What Is a Firewall Misconfiguration?

A firewall misconfiguration occurs when firewall settings create unnecessary or unintended risk.

Examples might include:

A high quality firewall cannot compensate for poor configuration.

How Often Should Firewall Rules Be Reviewed?

There is no universal interval that fits every organization.

The appropriate frequency depends on:

But the key principle is simple:

Firewall rules should not be created and then forgotten.

The FTC recommends reviewing firewall access controls periodically.

Organizations should also consider reviews after significant events such as:

What Questions Should I Ask During a Firewall Review?

A useful firewall review should attempt to answer:

1. Which services are exposed to the internet?

2. Does each exposed service still have a legitimate business purpose?

3. Which remote access methods are enabled?

4. Is multifactor authentication required?

5. Are administrative interfaces exposed?

6. Which vendors have access?

7. Are old firewall rules still present?

8. Are unused services disabled?

9. Is the firewall software current?

10. Are threat prevention capabilities enabled and updated?

11. Are security events logged?

12. Who receives important alerts?

13. Are separate network segments used where appropriate?

14. Is guest WiFi separated from the business network?

15. Are IoT devices appropriately isolated?

16. Is the firewall configuration backed up?

17. Are configuration changes documented?

18. Who has administrative access to the firewall?

Those questions turn the conversation from:

“Do we have a firewall?”

into:

“Are we effectively managing our firewall?”

Why Should Guest WiFi Be Separate From the Business Network?

The FTC recommends separating guest WiFi from the primary business network.

The reason is straightforward.

A customer or visitor generally needs:

internet access.

They generally do not need access to:

business computers

servers

printers

phones

security cameras

financial systems

administrative interfaces

Segmentation creates that separation.

The same principle can apply to employee personal devices and other equipment with different trust requirements.

Should Security Cameras Be on the Same Network as Business Computers?

Not necessarily.

Security cameras are computers with operating systems, network connections, credentials, and software.

They can also contain vulnerabilities.

Placing different device types into appropriate network segments can limit unnecessary communication.

For example:

Why should a lobby camera need unrestricted access to an accounting server?

In many environments, it should not.

This is where thoughtful network design becomes part of cybersecurity.

Should Firewall Administration Be Accessible From the Internet?

As a general security principle, administrative interfaces should not be exposed more broadly than necessary.

CISA has specifically recommended avoiding internet based management of infrastructure devices and using secure methods for administration.

If remote management is necessary, organizations should use carefully controlled, strongly authenticated access methods.

The firewall administration interface is exceptionally sensitive.

An attacker who gains control of the firewall may gain significant influence over the network it protects.

Who Should Have Administrator Access to the Firewall?

Only people who genuinely require administrative privileges.

Administrative access should follow the principle of least privilege.

That means:

Give people the access necessary to perform their responsibilities and no more.

Firewall administrator accounts should receive particularly strong protection.

Organizations should consider:

An account should not remain active simply because nobody remembered to remove it.

Can a Firewall Tell Me Someone Is Attacking My Network?

Often, it can provide valuable evidence.

Depending on the firewall and configuration, logs may record:

That information can help answer:

Who attempted the connection?

What were they trying to reach?

Was it blocked?

Was anything permitted?

Was authentication attempted?

Did a related event occur afterward?

This connects directly with the previous article in this series:

How Do I Know If Someone Is Trying to Hack My Network?

A firewall can provide part of the evidence.

But the logs need to be retained, monitored, and interpreted.

Blocking an Attack Is Good. Knowing It Happened Is Better.

Imagine your firewall successfully blocks repeated attempts to access a service.

Good.

The firewall did its job.

But the activity may still tell you something valuable.

Why is that service being targeted?

Is it actually exposed?

Are attempts increasing?

Are multiple locations seeing the same behavior?

Did any attempt succeed?

Are other systems showing related activity?

This is where firewall security and monitoring intersect.

Prevention provides protection.

Logging provides evidence.

Monitoring provides awareness.

Investigation provides context.

Is It Normal for My Firewall to Block Traffic?

Yes.

Public facing networks routinely encounter unsolicited internet traffic.

A firewall blocking traffic does not automatically mean your organization is experiencing a sophisticated targeted attack.

It may simply mean:

The firewall is doing its job.

This distinction can prevent unnecessary fear.

A log containing blocked traffic is not automatically evidence of compromise.

Security professionals should evaluate:

What matters most is not simply:

“Did somebody knock?”

It is:

“Did anybody get through?”

and

“What happened afterward?”

Should I Block Every Suspicious IP Address?

Blocking known malicious sources can be valuable.

But attempting to manually block every suspicious address on the internet is not a complete security strategy.

Attackers can use:

If a vulnerable service remains exposed, endlessly adding blocked addresses does not address the root cause.

The more important questions are:

Why is the service exposed?

Does it need to be?

Is it patched?

Is access restricted?

Is MFA enabled?

Can we monitor it?

A Firewall Should Help Reduce Attack Surface

One of the most valuable roles a firewall plays is reducing unnecessary exposure.

Instead of presenting hundreds of potential doors to the public internet, an organization should expose only what is genuinely required.

Every unnecessary service removed is one less thing that needs to be:

patched

monitored

authenticated

investigated

and

defended.

Security is often improved not by adding another complicated control but by removing something that never needed to be exposed in the first place.

How Do Firewalls Relate to Zero Trust?

Zero Trust is a security approach based on the idea that access should not automatically be trusted simply because a person or device is already inside a particular network.

Instead, organizations evaluate identity, device, access requirements, and other contextual factors.

This does not necessarily make firewalls obsolete.

It changes how the broader security architecture is designed.

Network segmentation, identity controls, access policies, monitoring, and authentication can work together.

The security philosophy becomes:

Do not automatically trust.

Verify appropriately.

Limit access.

Monitor behavior.

What Happens If My Firewall Goes Down?

A firewall failure can have major operational consequences.

Depending on network design, it may affect:

This reveals another important point:

A firewall is not only a security device.

In many businesses, it is also a critical operational device.

That means availability monitoring matters.

A business should know when:

The firewall stops responding.

A WAN connection fails.

A VPN tunnel drops.

A backup circuit activates.

Connectivity changes.

Security and network availability frequently overlap.

This Is Where ADAM and USA Telecom Fit

USA Telecom and the ADAM platform approach network infrastructure from a visibility and operational awareness perspective.

The firewall is one piece of a much larger environment.

That environment may include:

Internet circuits

routers

firewalls

VPNs

voice services

wireless networks

branch locations

cloud applications

servers

critical network devices

Monitoring helps answer questions that the firewall alone cannot always answer.

For example:

Is the firewall reachable?

Did the primary internet circuit fail?

Did the secondary circuit take over?

Is a branch location offline?

Did a VPN tunnel drop?

Is packet loss increasing?

Did network behavior change?

Is the problem the firewall, the carrier, the application, or something else?

That information can help shorten the distance between:

“Something is wrong.”

and

“We understand what needs to be investigated.”

A Firewall Without Monitoring Can Still Leave Questions

Imagine a firewall at a remote office.

At 1:17 AM, the device stops responding.

What happened?

Maybe:

The monitoring alert does not automatically provide the answer.

But without the alert, nobody may know there is a question.

That is the value of visibility.

Detection starts the investigation.

Firewalls Protect. Monitoring Observes. People Investigate.

That relationship is worth emphasizing.

A firewall can:

Allow.

Block.

Inspect.

Segment.

Log.

A monitoring platform can:

Watch.

Measure.

Detect change.

Generate awareness.

A technician can:

Validate.

Correlate.

Troubleshoot.

Escalate.

Remediate.

No single component replaces the others.

Together, they create a much stronger operational model.

15 Questions to Ask Your IT Provider About Your Firewall

Business owners do not need to know every command required to configure a firewall.

But they should know what questions to ask.

1. What firewall model do we have?

2. Is it currently supported by the manufacturer?

3. What software or firmware version is running?

4. When was it last updated?

5. Which services are exposed to the internet?

6. Why are they exposed?

7. Who has administrator access?

8. Is multifactor authentication enabled for administrators?

9. Which vendors have remote access?

10. Is our guest network separated from our business network?

11. Are our cameras and IoT devices appropriately segmented?

12. Are intrusion prevention and security services enabled?

13. Are firewall logs being retained?

14. Who receives security and availability alerts?

15. When were the firewall rules last reviewed?

If your organization cannot confidently answer those questions, that does not automatically mean the firewall is insecure.

But it does identify areas worth investigating.

The Better Question Is Not “Do We Have a Firewall?”

Almost every business understands that it should have a firewall.

The more useful questions are:

Is it configured correctly?

Is it current?

Is it supported?

Is access restricted appropriately?

Are unnecessary services exposed?

Are remote users protected by MFA?

Are guest and IoT networks segmented appropriately?

Are old rules being removed?

Are security features actually enabled?

Are logs being collected?

Is anyone monitoring it?

Would we know if it stopped working?

Would we know if something changed?

That is where firewall ownership becomes firewall management.

Key Takeaway

A firewall is one of the most important pieces of technology protecting a business network.

But owning a firewall does not automatically create a secure network.

A firewall must be:

Properly selected.

Properly configured.

Properly patched.

Properly segmented.

Properly monitored.

Properly managed.

And it must exist alongside other security controls.

The cybersecurity goal should not be:

“Buy one device that stops everything.”

It should be:

Reduce unnecessary exposure.

Control access.

Protect identities.

Patch vulnerabilities.

Segment systems.

Monitor important infrastructure.

Detect meaningful changes.

Investigate suspicious activity.

Respond when necessary.

A firewall is an extremely important part of that strategy.

But the strongest security does not depend on one wall.

It depends on layers.

Frequently asked questions

Does a firewall stop hackers?

A properly configured firewall can block many unauthorized network connections and significantly reduce exposure to attacks. However, it cannot prevent every cybersecurity threat. Effective security also requires controls such as multifactor authentication, patch management, endpoint security, monitoring, backups, secure remote access, and employee awareness.

Can hackers get through a firewall?

Yes. Attackers may exploit permitted services, vulnerable applications, compromised credentials, phishing, third party access, misconfigurations, or vulnerabilities in internet facing infrastructure. A firewall remains important, but it should be part of a layered security strategy.

Is a firewall enough to protect a small business?

No. A firewall is an important security control but should not be the only one. Small businesses should also consider MFA, software updates, endpoint protection, secure remote access, backups, employee training, monitoring, vulnerability management, and incident response.

Do small businesses need a firewall?

Businesses should use appropriate network security controls to manage communications between trusted and untrusted networks. The specific firewall architecture depends on the business's environment, risk, applications, locations, and regulatory requirements.

What does a firewall block?

A firewall blocks or permits network traffic based on configured security rules. Those rules can consider source, destination, service, application, user, network, and other criteria.

Does a firewall protect against viruses?

Some advanced firewalls include malware inspection and threat prevention capabilities, but businesses should also use endpoint security. No single security technology detects every form of malicious software.

Does a firewall prevent ransomware?

A firewall can reduce ransomware risk by limiting unauthorized access, controlling remote services, inspecting traffic, and segmenting networks. However, ransomware can enter through phishing, stolen credentials, vulnerable applications, compromised vendors, and other paths.

Does a firewall stop phishing?

Not completely. Firewalls and related security services may block access to known malicious websites or infrastructure, but employee awareness, email security, MFA, identity protection, and other controls are also important.

Does a firewall protect Microsoft 365?

A firewall can control network traffic to cloud applications, but protecting Microsoft 365 also requires identity security, MFA, appropriate administrative controls, login monitoring, email security, and secure account management.

Do firewalls need updates?

Yes. Firewalls run software and firmware that can contain vulnerabilities. Security appliances should be maintained, patched, and kept within supported product lifecycles.

Can a firewall itself be hacked?

Security appliances can contain software vulnerabilities or be compromised through weak credentials, exposed management interfaces, unsafe configuration, or other weaknesses. Firewalls themselves therefore require security controls.

What is a firewall rule?

A firewall rule defines which network communications should be allowed or blocked. Rules can use criteria such as addresses, ports, protocols, applications, users, and security zones.

How often should firewall rules be reviewed?

The appropriate schedule varies by organization, but firewall rules should be reviewed periodically and after significant network or business changes. Temporary, obsolete, and overly broad rules should be identified and addressed.

Should guest WiFi be separate from the business network?

Yes. The FTC recommends separating guest WiFi from the primary business network so guest and personal devices do not have unnecessary access to business systems.

Should security cameras be on a separate network?

Segmentation can reduce unnecessary communication between security cameras, IoT devices, employee systems, servers, and other infrastructure. Appropriate design depends on the business and technology environment.

Should I expose firewall management to the internet?

Administrative interfaces should not be exposed more broadly than necessary. Remote management should use strongly authenticated and appropriately restricted access methods.

What is network segmentation?

Network segmentation divides a network into separate logical or physical areas and limits communication between them. It can reduce unnecessary access and help contain the impact of a compromise.

What is a next generation firewall?

A next generation firewall generally combines traditional firewall functions with capabilities such as application control, intrusion prevention, threat detection, user identification, advanced VPN services, and other security features.

What is intrusion prevention?

Intrusion prevention analyzes activity for signs of known malicious behavior and can automatically block certain detected threats depending on configuration.

How do I know whether my firewall is working?

Businesses should verify configuration, review logs, maintain software updates, validate security policies, test appropriate controls, and monitor the firewall and its network connections for availability and important events.

Can a firewall tell me if someone is trying to hack me?

Firewall logs and security features may identify blocked connection attempts, authentication activity, exploit attempts, suspicious applications, and other events. Those events require context to determine whether they represent normal internet activity, attempted attacks, or successful compromise.

Sources

Editorial note

Firewalls, security architectures and appropriate controls vary significantly between organizations. Evaluate configuration and security recommendations against your business requirements, technology environment, regulatory obligations, risk profile and the manufacturer’s own guidance.

USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business running a 24/7 NOC. We monitor networks, circuits and firewalls for regulated and defense-supply-chain organizations.

← More from the ADAM Pulse Knowledge Base