A firewall is a security device or software that sits between your network and the internet and decides which traffic is allowed through. It blocks unrequested inbound connections, filters outbound traffic against policy, and on a business network is usually the single most important piece of security hardware you own.
What a firewall actually does
- Blocks unsolicited inbound traffic — anything from the internet that your network did not ask for is dropped by default
- Filters outbound traffic — stops staff devices reaching known-malicious sites and stops malware calling home
- Segments the network — keeps guest Wi-Fi, payment systems and staff devices apart so a problem in one does not spread
- Runs a VPN — gives remote staff an encrypted way back into the office network
- Logs everything — a record of what connected where, which matters after an incident
Hardware firewall vs software firewall
The hardware firewall is the box where your internet connection enters the building. It protects the whole network at once and is where business-grade security lives. The software firewall is built into Windows and macOS and protects one device wherever it is — useful for laptops that leave the office, but no substitute for the network firewall.
Next-generation firewalls
A modern business firewall does more than allow and block ports. A next-generation firewall adds intrusion prevention, application awareness, content filtering, and threat feeds that update automatically. For a small business this is normally delivered as a subscription on the firewall appliance, and it is the part that keeps working as new threats appear. Firewall management is part of our business network setup and cybersecurity services.
Common mistakes
- Using the modem/router the internet provider supplied as the only firewall
- Never installing firmware updates, so the firewall itself becomes the weak point
- Leaving remote-access ports open to the whole internet instead of behind a VPN
- A flat network where guest Wi-Fi can reach servers and payment systems — see cloud vs on-premise for why segmentation matters either way
- Letting the threat-prevention subscription lapse
Not sure what is protecting your network? See our network setup service or book a review with our Edmonton team.
Frequently asked questions
Is the router from my internet provider a firewall?
It has basic firewall features, but it is built to a price, rarely updated, and not designed for business security or segmentation. Most businesses replace it with, or put a proper firewall behind, the provider’s box.
Do I still need a firewall if everything is in the cloud?
Yes. Your office network, staff devices and any on-site equipment still need protecting, and the firewall also controls and secures how you reach those cloud services.
How often does a firewall need attention?
Firmware updates as they are released, a policy review a few times a year, and log monitoring ongoing. On a managed plan this happens in the background.
How does Scandifix help?
We size, install and configure a business firewall, set up segmentation and remote-access VPN, keep the firmware and threat subscriptions current, and monitor the logs. See our managed IT services.