Security (Imunify360, ModSecurity)

Firewalls Explained: Types and How to Set One Up

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (8 sections)

A firewall decides which network traffic may reach a computer or network and which may leave it. Every server on the internet needs one, from a laptop to a hosting server. This guide explains how firewalls work, the main types, how to set one up well on a server you manage, and what is already done for you on Domain India hosting.

Key takeaways

A firewall allows or blocks traffic using rules based on addresses, ports, protocols and, in newer products, the application and content. The safe default is simple: block everything inbound, then open only the ports you actually use. On Domain India shared hosting the server firewall is managed for you and you can't change it. On your own VPS or server, the firewall is your job: nftables, firewalld or ufw on Linux, Windows Defender Firewall on Windows.

1. What a firewall does

A firewall sits between a trusted side (your server or office network) and an untrusted side (the internet). For each packet or connection it checks a list of rules in order and either allows it, drops it silently, or rejects it with an error.

Rules usually look at:

  • Source and destination IP address: who is talking to whom.
  • Port and protocol: which service, for example TCP 443 for HTTPS or TCP 22 for SSH.
  • Direction: inbound (from the internet to you) or outbound (from you to the internet).
  • Connection state: whether a packet belongs to a connection that is already allowed.

Firewalls began in the late 1980s as simple packet filters; stateful and application-aware firewalls followed. All three ideas are still in use.

2. How firewalls inspect traffic

TechniqueWhat it checksStrengthLimit
Packet filtering (stateless)Each packet's header: IP, port, protocolVery fast and simpleNo memory of connections, so rules must allow reply traffic by hand
Stateful inspectionHeaders plus the state of each connectionAllows replies automatically; the standard for serversDoesn't read the content of the traffic
Proxy (application gateway)Full requests at the application layerCan filter URLs and content; hides internal addressesSlower; one proxy per protocol
Next-generation (NGFW)Applications, users and content, often with IDS/IPSDeep visibility and controlCostly; decrypting HTTPS needs careful handling

Two related terms come up often:

  • IDS/IPS (intrusion detection or prevention system). It watches traffic for known attack patterns. An IDS only alerts; an IPS also blocks.
  • Deep packet inspection (DPI). It reads the content of packets, not just the headers. It can only see inside HTTPS if the firewall decrypts it.

3. Types of firewall by where they run

TypeWhere it runsProtectsExamples
Network firewallAt the edge of a network, as an appliance or virtual applianceEvery device behind itOffice or data-centre firewalls from vendors such as Fortinet, Palo Alto Networks, Cisco and Check Point, or open-source pfSense and OPNsense
Host-based firewallOn the server or PC itselfThat one machinenftables, firewalld or ufw on Linux; Windows Defender Firewall
Cloud firewallIn a cloud provider's network, in front of your serverServers in that cloudCloud security groups and network firewalls
Web application firewall (WAF)In front of or inside the web serverWebsites and APIsModSecurity, Coraza, CDN WAFs

A network firewall suits an office with many devices. A single server on the internet mainly needs a well-configured host-based firewall, and a WAF if it runs a website. Our guide to the web application firewall covers the WAF layer in detail.

4. The rules that matter most

  1. Deny by default.
    Set the inbound policy to drop, then allow only what you need. A rule list that allows everything and blocks a few "bad" ports protects very little.
  2. Allow established connections.
    With a stateful firewall, one rule lets reply traffic back in, so outbound requests work normally.
  3. Open only the services you run.
    A web server usually needs 80 and 443. Add SSH (22) only if you use it, and prefer limiting it to your own IP addresses.
  4. Never expose databases.
    MySQL (3306), PostgreSQL (5432), Redis (6379) and MongoDB (27017) should not be open to the internet. Reach them through an SSH tunnel or a private network.
  5. Rate-limit logins.
    Limit new connections to SSH and mail logins, and use a tool such as fail2ban to block addresses that keep failing.
  6. Log what you drop, briefly.
    Logging helps you debug, but log with a rate limit so an attack doesn't fill the disk.
  7. Keep a way back in.
    Before you change SSH rules on a remote server, keep your current session open and test a new login from a second terminal.
Test before you lock yourself out

The most common firewall mistake on a remote server is enabling a deny-all policy before allowing SSH. Add the allow rule first, apply, test a new connection, and only then close your old session.

5. Setting up a firewall on your own Linux server

This section applies to a VPS or server you manage yourself, not to shared hosting, where you cannot change the server firewall.

Modern Linux distributions use nftables in the kernel. Most people manage it through a friendlier front end:

  • firewalld on AlmaLinux, Rocky Linux and RHEL.
  • ufw on Ubuntu and Debian.

A minimal web server with ufw:

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit 22/tcp        # SSH, rate-limited
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

The same with firewalld:

bash
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

Two traps to know:

  • Docker bypasses ufw and firewalld rules for published ports. A container started with -p 5432:5432 is reachable from the internet even if your firewall looks closed. Publish ports on 127.0.0.1 only, for example -p 127.0.0.1:5432:5432, or manage the rules in Docker's own chain.
  • IPv6 needs rules too. If the server has an IPv6 address, check that your policy covers it. ufw and firewalld handle both when configured normally; hand-written rules often forget IPv6.

On Windows servers, use Windows Defender Firewall with Advanced Security, keep inbound traffic blocked by default and allow only the ports your applications need. Avoid exposing Remote Desktop (3389) to the whole internet; restrict it to known addresses or put it behind a VPN.

6. Benefits and limits

A firewall gives you
  • Fewer services reachable by attackers
  • Protection for services that should stay private, such as databases
  • Control over what your server can connect to outbound
  • Logs that show scanning and attack attempts
A firewall can't
  • Fix a vulnerable website plugin or weak password
  • Stop attacks carried inside allowed traffic, such as a malicious form submission to port 443
  • Absorb a large DDoS flood by itself; that needs upstream protection
  • Replace updates, backups and monitoring

A firewall is one layer. Combine it with updates, key-based SSH, strong passwords with two-factor authentication, a WAF for websites, and tested backups. Review the rules every few months, remove anything no longer used, and after each change scan the server from outside (for example nmap -Pn yourserverip) to confirm only the intended ports answer.

7. Firewalls on Domain India hosting

Shared hosting (cPanel, DirectAdmin, Webuzo, Windows). The server firewall is configured and maintained by us for everyone on the server, and customers can't change it. When we checked on 20 September 2026, our cPanel and DirectAdmin servers ran the CSF firewall together with Imunify360, and the cPanel servers also ran Imunify360's DoS protection and a ModSecurity web application firewall. What this means for you:

  • The ports customers need are open, including web, mail, FTP and the control panel. The full, measured list is in Domain India hosting port numbers.
  • MySQL port 3306 is closed from outside on every shared server. Connect through an SSH tunnel instead; see how to connect to the MySQL database.
  • Outgoing connections are filtered too on our cPanel and DirectAdmin servers. For example, MongoDB's port 27017 is not allowed out, so MongoDB Atlas can't be reached from shared hosting; use the App Platform, a VPS, or MySQL or PostgreSQL instead.
  • Jailed SSH access is available on every Linux shared hosting plan. It is off by default; ask support to enable it. Login is by SSH key. See enabling and accessing jailed SSH.

If you think the firewall is blocking you, for example you can't reach your control panel from one network, open a ticket with your public IP address and the time it happened.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

VPS. A Domain India VPS is self-managed. You get root access and set up the firewall yourself, following section 5. See the VPS security checklist for the rest of the hardening.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Prices on the cards are Domain India list prices and exclude 18% GST.

Frequently asked questions

What is a firewall in simple terms?

A firewall is a set of rules that decides which network traffic may reach a computer or network and which may leave it. It allows or blocks connections based on addresses, ports, protocols and, in newer products, the application or content.

What is the difference between a stateless and a stateful firewall?

A stateless firewall checks each packet on its own. A stateful firewall remembers connections, so it lets reply traffic back in automatically and can block packets that don't belong to any allowed connection. Stateful firewalls are the standard for servers today.

Do I need a firewall if my website uses HTTPS?

Yes. HTTPS encrypts traffic, but it doesn't stop anyone connecting to other services on the server. A firewall keeps everything except the services you need unreachable.

Is a web application firewall the same as a firewall?

No. A network firewall controls which connections are allowed by IP address and port. A web application firewall reads the content of web requests and blocks attacks such as SQL injection inside traffic that the network firewall allows.

Can I change the firewall on Domain India shared hosting?

No. The server firewall on shared hosting is managed by Domain India for every account on the server. If you think it is blocking you, open a support ticket with your public IP address and the time of the problem.

Who manages the firewall on a Domain India VPS?

You do. VPS plans are self-managed with root access, so you choose and configure the firewall, for example firewalld or ufw on Linux.

Ready to go further? Read about the web application firewall, compare cPanel hosting and VPS plans, or open a ticket if you think a firewall rule is blocking you.

Blocked by a firewall?

Tell us your public IP address, what you were trying to reach and when, and our team will check the server firewall for you.

Open a support ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Firewalls Explained: Types and Best Practices | Domain India