Firewalls and Intrusion Detection/Prevention Systems (IDS/IPS)
What Is a Firewall?
A firewall is a network security device or software that monitors incoming and outgoing traffic and decides whether to allow or block it based on a defined set of security rules, acting as a barrier between trusted internal networks and untrusted external networks.
Types of Firewalls
| Type | Description |
|---|---|
| Packet-Filtering Firewall | Inspects packets based on IP address, port, and protocol |
| Stateful Inspection Firewall | Tracks the state of active connections for smarter filtering |
| Proxy Firewall | Acts as an intermediary between users and the internet |
| Next-Generation Firewall (NGFW) | Combines traditional filtering with deep packet inspection and threat intelligence |
Intrusion Detection and Prevention Systems (IDS/IPS)
An IDS monitors network or system activity for suspicious behavior and alerts administrators, while an IPS goes a step further by actively blocking or preventing detected threats in real time.
IDS vs IPS
The key difference is action: IDS is a passive, monitoring-only system that generates alerts, whereas IPS is placed inline with traffic and can automatically drop malicious packets or reset connections to stop an attack as it happens.
Ready to master Cybersecurity Training Course?
Join Uncodemy's hands-on training and build real-world cybersecurity skills with expert mentors.