Computer Science · Ch 12 — Security Aspects
Firewall
Firewall
A firewall is a network security system designed to protect a trusted private network from unauthorised access or traffic coming from an untrusted outside network — for example, the Internet, or even different sections of the same network to which the private network is connected. Think of it as a guarded gate between two worlds: everything that tries to cross from the untrusted side into the trusted side must pass through this gate and be checked.
The firewall can be implemented in software, in hardware, or in both. Software firewalls run as programs on individual computers or servers, while hardware firewalls are dedicated physical devices placed between networks. Many organisations use a combination of both for stronger protection.
A firewall matters because of the way malware spreads. A worm, for instance, has the capability to move across networks and infect other computers on its own. The firewall acts as the first barrier against such malware — it stands between your network and the outside world, blocking malicious traffic before it can reach your machines.
A firewall acts as a network filter. Based on predefined security rules, it continuously monitors and controls both incoming and outgoing traffic. Every packet of data that tries to enter or leave the network is examined against these rules, and only traffic that matches the allowed conditions is permitted to pass.
Here is a concrete example of how a rule works. In a school LAN, a rule can be set in the firewall so that a student cannot access data from the finance server, while the school accountant can access the finance server. The firewall enforces this distinction automatically — it does not rely on human judgment at the moment of access, but on the rules that were configured in advance.
So the key ideas to carry forward are:
- Purpose: protect a trusted private network from unauthorised access or traffic from an untrusted network. …
Drawn by us to help you understand the concept clearly, and verified to make sure it's accurate. For exams, practice from your NCERT textbook's own diagram.
The figure is a simple network diagram built around one central idea: a firewall is a boundary object. On the left sits a small local area network, drawn as three desktop computers connected by green lines to a single vertical trunk line labelled LAN. That trunk line runs straight into a red-orange brick wall, and the wall itself carries the label Firewall. On the right of the wall is a second network labelled WAN, drawn as eight desktop computers arranged in a branching tree — one machine connects to two others, and each of those connects to two more. The wall sits exactly between the two networks, with the LAN trunk on one side and the WAN tree on the other.
The layout is doing real work. The LAN is small, flat, and uniform — three machines on one shared line, the picture of a trusted, contained private network. The WAN is larger and more irregular, a branching structure that suggests something sprawling and less controlled, the outside world. The firewall is not inside either network; it is placed precisely at the seam where the LAN trunk meets the WAN, so that every path from one side to the other must pass through the wall. There are no arrows in the figure, but the geometry itself implies direction: traffic from the WAN heading into the LAN, and traffic from the LAN heading out, both have to cross the firewall. Nothing bypasses it. …