Skip to main content

What Is a Firewall? Definition, Operation, and Firewall Types

·2 min read·262 words

A firewall is a network security device that filters traffic between two networks (typically the Internet ↔ an enterprise LAN) according to predefined rules. Modern firewalls (NGFW — Next-Generation Firewall) incorporate IPS, AV, URL filtering, and SSL inspection.

Firewall Types

  • Packet filter: stateless L3/L4 filtering (basic iptables)
  • Stateful inspection: tracks sessions (SYN, ACK) to make filtering decisions
  • Application proxy: receives, inspects, and retransmits traffic (BlueCoat, Squid)
  • NGFW (Next-Gen): L7 application awareness + IPS + AV + Content-ID
  • WAF (Web Application Firewall): specialized in HTTP/HTTPS traffic

NGFW Functions

  • Stateful inspection from L3-L7
  • Application identification (e.g., detects Teams within HTTPS)
  • User identification (AD/LDAP integration)
  • IPS (Intrusion Prevention System)
  • Inline antivirus
  • URL filtering (category-based)
  • SSL/TLS decryption
  • Integrated SD-WAN
  • IPsec VPN + SSL-VPN
  • DNS Security

Leading Firewalls in 2026

  • Palo Alto Networks: Gartner leader for 13 consecutive years
  • Fortinet FortiGate: leader for the mid-market and mid-sized enterprises, Security Fabric
  • Check Point: enterprise and compliance
  • Cisco Secure Firewall (Firepower): Cisco SecureX integration
  • Stormshield: ANSSI-certified French leader
  • Sophos XGS: SMBs and mid-sized enterprises
  • WatchGuard: straightforward security for SMBs
  • pfSense / OPNsense: open source, self-hosted

Basic Firewall Rules

  • Source: IP / range / zone / user / group
  • Destination: same criteria
  • Service: TCP/UDP ports or L7 apps
  • Action: allow, deny, log, count
  • Exception handling: implicit deny at the end

Deployment

  • Perimeter: between the Internet and LAN (standard)
  • Internal segmentation: between internal zones
  • DMZ: dedicated zone for public-facing services (web, email, VPN)
  • Data center: application/tenant isolation
  • Cloud: virtual firewalls (AWS, Azure, GCP)

Order from OPTINOC

FortiGate, Palo Alto, Cisco, Stormshield, and pfSense available from OPTINOC. Turnkey configuration. Quotes within 2h.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote