Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Guidelines on Firewalls and Firewall Policy



Karen A. Scarfone, Paul Hoffman


Firewalls are devices or programs that control the flow of network traffic between networks or hosts employing differing security postures. This publication provides an overview of several types of firewall technologies and discusses their security capabilities and their relative advantages and disadvantages in detail. It also makes recommendations for establishing firewall policies and for selecting, configuring, testing, deploying, and managing firewall solutions. [Supersedes SP 800-41 (January 2002):]
Special Publication (NIST SP) - 800-41 Rev 1
Report Number
800-41 Rev 1


Firewall policy, firewalls, host-based firewalls, network firewalls, network security, packet filtering, perimeter security, personal firewalls, proxies


Scarfone, K. and Hoffman, P. (2009), Guidelines on Firewalls and Firewall Policy, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed June 24, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created September 28, 2009, Updated February 19, 2017