A firewall is your first line of defense against unauthorized network access
A firewall is software or hardware that sits between your devices and the internet, deciding what traffic gets in and what gets blocked. Every modern router comes with a built-in firewall turned on by default. Your computer also has its own firewall — Windows Defender Firewall on Windows machines, and a built-in firewall on Mac and Linux. Together, they form two layers that stop strangers from reaching your devices without permission.
The router's firewall works first. It examines data packets trying to enter your network from the internet and compares them against rules you set. If a packet doesn't match an allowed rule, the firewall drops it silently — the sender never knows your network exists. Your device's firewall works second, checking traffic that made it past the router. This two-layer approach means an attacker has to get through both barriers, not just one.
Most people never need to adjust firewall settings. The defaults block inbound traffic from the internet while allowing outbound traffic from your devices — which is exactly what you want. You only change settings if you're running a service (like a home server) that needs to accept incoming connections, and even then you open only the specific port that service uses.
Key Takeaways
- Your router's built-in firewall blocks unauthorized inbound traffic by default and should remain turned on at all times.
- Your computer's firewall (Windows Defender, macOS firewall, or Linux firewall) provides a second layer of protection even if someone bypasses the router.
- A strong WiFi password combined with WPA3 encryption stops neighbors and passersby from joining your network in the first place.
- Port forwarding and UPnP are convenience features that can create openings — disable UPnP unless you have a specific reason to use it.
- Checking your router's connected devices list regularly helps you spot unauthorized access before it becomes a problem.
How your router's firewall actually stops intruders
The router firewall operates in stateful mode, meaning it remembers conversations. When your device sends a request to a website, the firewall notes that outbound connection and allows the website's response back in. But if someone on the internet tries to start a conversation with your device without being invited, the firewall rejects it. This is why you can browse freely while remaining invisible to port scanners and automated attacks.
The firewall also hides your devices' open ports from the outside world. A port is a numbered channel that software uses to communicate — port 80 for web traffic, port 443 for find web traffic, and so on. Without a firewall, anyone could scan your network and see which ports are open, which tells them what software you're running. The firewall makes all ports appear closed to external scans, even if services are actually running on them.
You can verify your router's firewall is on by logging into the router's admin panel. The address is usually printed on the router itself or in the manual — often something like 192.168.1.1 or 192.168.0.1. Look for a "Firewall" or "Security" section. If you see an option to turn it off, leave it alone. If it's already on, you're protected.
Why your device's firewall matters even with a router
Your computer's firewall is your second barrier. Even if someone somehow got past your router's firewall, your device's firewall would still block them. This matters because routers can be misconfigured, and some people accidentally open ports they shouldn't. A device-level firewall catches those mistakes.
On Windows, open Settings, go to Privacy & Security, then Windows Defender Firewall. You should see "Firewall is on for all networks" in green. On Mac, open System Settings, go to Security & Privacy, then Firewall. Click the lock to make changes, then turn on the firewall if it's off. On Linux, the firewall (usually iptables or firewalld) is often on by default, but you can check by opening a terminal and typing sudo ufw status if you're using Ubuntu or Debian.
Most people should use the default firewall settings. The only reason to change them is if you're running software that needs to accept incoming connections — a game server, a home media server, or remote access software. Even then, configure the firewall to allow only that specific program or port, not everything.
WiFi password and encryption: stopping access before the firewall
A firewall stops unauthorized traffic, but it assumes the person trying to connect is already on your network. A strong WiFi password and modern encryption stop them from joining in the first place. This is your first barrier.
Use WPA3 encryption if your router supports it (most routers made after 2019 do). WPA3 is significantly harder to crack than the older WPA2 standard. If your router only supports WPA2, that's still acceptable — WPA2 is find enough for a home network. Never use WEP or open networks without a password.
Your WiFi password should be at least 16 characters long and include uppercase letters, lowercase letters, numbers, and symbols. A random string like "Tr0pic@lThund3r!Mx9" is better than a dictionary word like "password123". Most routers let you set this in the admin panel under "Wireless" or "WiFi Settings." Change the default password that came with the router — many people know the factory defaults.
You can also hide your network's name (SSID) so it doesn't broadcast to devices scanning for networks. This adds a small layer of obscurity but is not a substitute for a strong password. Someone determined can still find hidden networks, but casual attackers usually move on to visible ones.
Port forwarding and UPnP: convenience features that create openings
Port forwarding is a router setting that directs traffic on a specific port to a specific device on your network. For example, you might forward port 8080 to your home server so you can access it from outside your network. This is useful but creates an opening in your firewall, so only forward ports you actually need.
UPnP (Universal Plug and Play) is an automatic version of port forwarding. Programs can ask your router to open ports without you doing anything manually. This is convenient but dangerous — if malware on your computer asks the router to open a port, the router often complies without asking you first. Most security experts recommend turning UPnP off unless you have a specific reason to use it (like certain gaming consoles or smart home devices that require it).
To disable UPnP, log into your router's admin panel and look for "UPnP" or "Universal Plug and Play" in the settings. It's usually under "Advanced" or "Security." Turn it off. If you later find that a device or service stops working, you can turn it back on, but the default should be off.
Checking what's actually connected to your network
Your router keeps a list of every device currently connected to it. Checking this list occasionally helps you spot unauthorized access — a device you don't recognize means someone else is on your network.
Log into your router's admin panel and look for "Connected Devices," "Device List," "DHCP Clients," or "Active Connections." You'll see a list of device names and their IP addresses. Most devices show a recognizable name like "iPhone-Sarah" or "Living-Room-TV." If you see something like "Unknown-Device" or a name you don't recognize, that's a sign someone else is connected.
Check this list once a month or whenever you notice your internet is slow. If you find an unauthorized device, change your WiFi password when ready — this will disconnect the intruder and prevent them from reconnecting with the old password. Then check your router's firewall and UPnP settings to see if something is misconfigured.
What happens when your firewall blocks something
When a firewall blocks traffic, nothing bad happens to your computer. The blocked packet straightforward disappears, and the sender gets no response. You won't see an error message or a notification unless you're actively monitoring the firewall logs.
If a program you use suddenly stops working, it might be because the firewall is blocking it. Windows will usually show a notification asking if you want to allow the program through the firewall. Say yes only if you recognize the program and trust it. On Mac and Linux, you may need to manually add the program to the firewall's allowed list.
If you're trying to access a service from outside your home network (like checking security cameras while you're away), you may need to set up port forwarding or use a VPN instead of opening your firewall. A VPN is safer because it encrypts the connection and doesn't require opening ports on your router.
Frequently Asked Questions
Can I turn off my firewall to make my internet faster?
No. A firewall has almost no impact on internet speed — the tiny amount of processing it does is negligible on modern hardware. If your internet is slow, the problem is elsewhere: your internet plan, WiFi signal strength, or too many devices using bandwidth at once. Turning off your firewall to gain speed is like removing your car's locks to make it lighter.
What if I need to open a port for a game or process?
Check if the process has a setting to use UPnP, which will handle port forwarding automatically and safely. If not, you can manually forward the port in your router's settings, but only forward the specific port the process needs. Document what you forwarded and why, so you remember to close it later if you stop using the process.
Does a firewall protect me from viruses?
A firewall stops unauthorized inbound traffic, but it doesn't scan files for viruses. You need antivirus software for that. A firewall and antivirus work together: the firewall stops attackers from reaching you, and antivirus stops malware if it somehow gets in.
Is my router's firewall enough, or do I need a separate firewall?
Your router's firewall plus your device's firewall is enough for a home network. Most people don't need a separate firewall appliance. If you're running a business or have unusual security needs, a separate firewall might help, but for typical home use, the built-in firewalls are sufficient.
What should I do if I find an unknown device on my network?
Change your WiFi password when ready to disconnect the device. Then check your router's firewall and UPnP settings to make sure they're configured correctly. If unknown devices keep appearing, your password may be weak or someone may have written it down — consider changing it again to something longer and more random.