What is a firewall?

A firewall decides which connections to the server are allowed.

What it is

A firewall lets through only the connections you allow. Everything else stays out, or does not go out. Typical is the path for HTTPS to the outside, and closed doors that nobody on the internet should reach: SSH only from known networks, database ports not public at all.

It does not decide who may sign in. It decides whether the door exists at all.

What it is made of

Rules are small and concrete. From where, to where, which port, allow or deny. One rule too open is a service you did not want to show. One rule too closed is a deploy that cannot connect, or a health check that stays red even though the process is running.

What goes wrong

In your own setup you maintain those rules per server and per environment. Dev and prod are not the same. What you open briefly for debugging often stays open. You notice gaps when something is reachable that should not be, or when a scanner finds them before you do.

What you otherwise look after yourself

The firewall does not replace sign-in inside the app. It only says which door exists at all. Who may walk through the door is auth’s decision.

How it shows up on MainPath

MainPath sets the server’s reachability with the project, instead of opening the rules by hand every time and then forgetting them.

All terms