Skip to main content

IT security

What is a firewall?

A firewall is the company's first line of defence against external attacks. See the difference between hardware, software and next-generation firewalls.

In short

A firewall is a security function that monitors and filters the traffic between your network and the internet, so unwanted connections are blocked before they reach your systems.

It acts as a doorman that decides, based on defined rules, which traffic may pass in and out. Every business with an internet connection needs a firewall, because it forms the first line of defence against attacks from the outside.

Three points are central: firewalls exist both as hardware at the network edge and as software on the individual computer, and the two complement each other; a next-generation firewall can also inspect the content of the traffic and stop known attack patterns; and a firewall is only as good as its rules, which must be maintained continuously as the business changes.

MI Support IT helps Danish businesses with the selection, setup and ongoing operation of firewalls as part of their overall IT security.

Back to the glossary

What is a firewall?

A firewall is a security function that monitors the traffic between your network and the internet and blocks anything that is not explicitly allowed. It acts as a doorman: based on a set of firewall rules, it decides which connections may pass in and out, and rejects the rest before it reaches your servers and computers. The Danish Centre for Cyber Security highlights network segmentation and control of inbound traffic as fundamental measures against external attacks, and the firewall is the tool that enforces exactly that.

A firewall is not a "set it and forget it" product, however. The rules must be maintained: every opening created for a new system and never closed again is a potential entry point for attackers.

Hardware or software firewall?

  • Hardware firewall: a physical device (or router function) at the network edge that protects the entire network as a whole: every machine behind it is covered. Standard in any business with its own network.
  • Software firewall: runs on the individual computer or server and protects that particular machine, including when the laptop travels to the home office or cafe Wi-Fi.

It is not an either-or. The hardware firewall protects the edge, the software firewall protects the machine, and with remote work and mobile devices both layers are necessary. Combine them with a VPN or a zero trust approach, so access always requires verification, wherever the user is.

What is a next-generation firewall (NGFW)?

A traditional firewall looks at sender, recipient and port, in other words who is talking to whom. A next-generation firewall (NGFW) also looks at the content: it can recognise which applications the traffic belongs to, inspect encrypted traffic, block known attack patterns (intrusion prevention) and filter access to malicious websites. Many NGFWs also connect to continuously updated threat intelligence, so new attack techniques are blocked shortly after they are first seen. For most businesses, an NGFW is today the standard choice at the network edge.

Is Windows' built-in firewall enough?

The honest answer: for private use, yes; as the only defence in a business, no. Windows' built-in firewall is a perfectly good software firewall, and it should be enabled on all machines. But it only protects the individual computer, it does not inspect the content of the traffic, and it is not centrally managed: you cannot see across the company whether the rules are actually consistent and correct everywhere. A business needs both: a central (preferably next-generation) firewall at the edge and managed software firewalls on the machines.

How MI Support IT can help

MI Support IT helps Danish businesses select, set up and operate the right firewall solution, including ongoing maintenance of rules, so old openings do not become new holes. The firewall is one layer in the overall defence alongside monitoring, updates and access control. Read more under IT security, or contact us for a review of your current setup.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.