Firewall User Protection
For a single home user who regularly surfs the Web and uses e-mail and instant messaging, a firewall’s primary job is to keep viruses from infecting files and prevent Trojan horses from entering the system and installing hidden openings called back doors, which can be used for access at a later time.
Firewall Network Perimeter Security
A firewall is often said to provide “perimeter security” because it sits on the outer boundary, or perimeter, of a network. The network boundary is the point at which one network connects to another.
If you have an extranet, an extended network that combines two or more LANs, the location of the “perimeter” becomes unclear. If you maintain a VPN with a supplier or business partner, the VPN should have its own perimeter firewall because your network boundary technically extends to the end of the VPN. Note that locating the firewall at the perimeter has one obvious benefit: it enables you to set up a checkpoint where you can block “bad things” like viruses and infected e-mail messages before they get inside. Another benefit is that a firewall enables you to log passing traffic, protecting the whole network at the same time. If an attack does occur, having a security subnet at the perimeter can minimize the damage.
Firewall Components
A firewall can contain many components, including:
- Packet filter
- Proxy server
- Authentication system
- Software that performs Network Address Translation (NAT)
Many firewalls make use of a bastion host, a machine that has no unnecessary services. A network that needs to connect to the Internet might have been a bastion host and a service network. Together, they are the only part of the organization exposed to the Internet.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics