In more detail
Firewalls run in hardware at the edge of a network or as software on a single computer. A good starting policy is to deny everything by default and open only the Ports a service needs. Web application firewalls go further and inspect HTTP requests themselves.