Firewalls can selectively permit traffic to go from inside the network to the Internet or other networks to provide more precise control of how employees inside the network use external resources. In other words, the firewall can act as a proxy server that makes high-level application connections on behalf of internal hosts and other machines. A single firewall product can provide both outbound packet filtering and outbound proxy services.
Protecting Critical Resources
Attacks on critical resources are becoming all too common. Worms are one type of attack. They “worm” their way into a computer in an e-mail attachment or a downloaded file, where they then replicate themselves. They are only slightly different than viruses, which also worm their way into a computer but then do much more destructive behavior than just replication. Trojan horses are similar to viruses; they contain malicious code that is hidden inside supposed harmless programs. Distributed Denial of Service (DDoS) attacks are just as harmful. They are caused when a hacker floods a server with requests, shutting down the server and making Web sites and networks that depend on that server unreachable.
Protecting Against Hacking
Hacking, in general, is the practice of infiltrating computers or networks to steal data, cause harm, or simply claim credit for getting inside. The impacts of this type of attack include:

Providing Centralization
A firewall centralizes security for the organization it protects. It simplifies the security-related activities of the network administrator, who typically has many other responsibilities. Having a firewall on the perimeter gives the network administrator a single location from which to configure security policies and monitor arriving and departing traffic.
Enabling Documentation
Every firewall should be configured to provide information to the network administrator in the form of log files. These log files record attempted intrusions and other suspicious activity, as well as mundane events like legitimate file accesses, unsuccessful connection attempts, and the like.
Providing for Authentication
Authentication is the process of logging into a server with a username and a password before being allowed access to protected information. Only users who have registered their username and password are recognized by the server and allowed to enter. The authentication process can also be performed at the firewall and can make use of encryption to protect the usernames and passwords transmitted from client to server (or client to firewall).
Contributing to a VPN
A firewall is an ideal endpoint for a VPN, which connects two companies’ networks over the Internet. A VPN is one of the safest ways to exchange information online.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics