— a multi-niche blog
A practical guide to setting up a home network firewall
Walk into any suburban fibro in Perth or a brick veneer in Brisbane and you'll find a Wi-Fi router glowing in the corner, a smart TV, laptops, a gaming console, and a growing pile of smart speakers, doorbells, and robot vacuums. Australian households have quietly become small IT departments, and most of us have not really thought through how to protect them. With the National Broadband Network now reaching most premises, and more people working from home since the pandemic shifted how we earn a crust, having a properly configured firewall is no longer optional. It is the single most important piece of kit between your data and the rest of the internet.
The Australian Cyber Security Centre regularly flags ransomware and credential-stealing attempts targeting home networks, particularly small businesses and home offices. A firewall acts like a fair dinkum bouncer at your network's front gate, inspecting traffic and deciding what gets in. Setting one up is not as scary as it sounds, and you do not need to be a tech wizard to get the basics right. Whether you prefer the plug-and-play approach of a modern router or the deeper control offered by a software firewall, the process follows a familiar rhythm: prepare, install, configure, and maintain.
What a firewall actually does
In plain terms, a firewall examines every packet of data trying to enter or leave your network and applies a set of rules to decide whether to allow or block it. Think of it as a customs officer at the border of your digital home. It can filter by source, destination, port, or protocol, and modern versions also handle intrusion detection, malware scanning, and parental controls. The two main flavours are hardware firewalls (often built into your router) and software firewalls (running on individual devices like your laptop or server).
The reason this matters more in Australia than it once did comes down to the way the NBN has changed the average household. Where older ADSL setups often sat behind a dynamic IP that changed constantly, many NBN connections now use static or semi-static addressing, which makes unprotected devices easier to find. Combine that with the explosion of internet-connected devices, and you have a much larger attack surface than the family PC of two decades ago. If you enjoy lifestyle write-ups that touch on home tech, you might find Arushi Villa covers related territory from a different angle.
Choosing between hardware and software
For most Aussie households, the best starting point is the router your ISP gave you, whether that's a Telstra Smart Modem, an Optus Ultra Wi-Fi modem, or an Aussie Broadband-supplied unit. These all ship with a basic firewall already turned on, but the defaults are often too permissive. If you want stronger control, swapping in a consumer-grade router from brands like ASUS, Netgear, or TP-Link gives you a more capable firewall with regular firmware updates.
Software firewalls still matter, even with a hardware firewall in front. Windows has had a built-in option since Windows XP, macOS silently runs an application-layer firewall, and Linux distros ship with iptables or nftables. Software firewalls are particularly useful for laptops that move between home Wi-Fi, the office, and the local library when you're cramming for a study session. They protect you on networks you do not control.
When weighing up options, it's worth thinking about what devices you actually want to shield and how comfortable you are with settings menus. If the choice between an off-the-shelf modem and a more advanced router has you stumped, you might as well settle the debate the way the team at E-Pragati settles theirs with would you rather questions. Whatever you pick, the goal is the same: a device that filters traffic before it reaches your gadgets.
Preparing your network before you start
Before touching any firewall settings, map out what is actually on your network. Most home networks use the 192.168.0.x or 192.168.1.x range, with the router acting as the gateway. Log into your router's admin page and check the device list. You'll likely be surprised how many devices show up: phones, tablets, smart TVs, game consoles, smart watches, and a growing collection of IoT gadgets.
Once you know what's connected, decide whether to segment your network. Many modern routers, including Telstra's latest modems and aftermarket options from ASUS and Netgear, support guest networks or VLAN-style separation. Putting smart home devices on a separate subnet from your work laptop is a simple but effective way to contain any compromise. If a dodgy smart bulb gets owned by a botnet, it cannot easily pivot to your computer.
Make a quick note of any services that need incoming connections. Online gaming on a PS5 or Xbox often wants specific ports opened, as does remote access to a home media server. Writing these down now saves frustration later, and it gives you a checklist when you start writing firewall rules.
Installing and switching on the firewall
If you're going with the router path, the install is mostly physical. Unbox the router, connect the NBN NTD or HFC connection to the WAN port, plug in the power, and follow the setup wizard. Most consumer routers now have apps that handle the heavy lifting, including the interfaces Telstra provides and competing mesh systems from Eero, Google Nest, and TP-Link's Deco line. The wizard will prompt you to change the default admin password, set a Wi-Fi network name and passphrase, and offer to enable automatic firmware updates. Say yes to all of these.
For a software firewall, the install usually means confirming the built-in option is enabled. On Windows, search for "Windows Security," open "Firewall & network protection," and verify all three profiles (Domain, Private, Public) are switched on. On macOS, head to System Settings, then Network, then Firewall. On Linux, tools like UFW make iptables approachable with simple commands like sudo ufw allow 22/tcp and sudo ufw enable.
Once installed, change every default password before going any further. "admin/admin" is a recipe for a bad day, and Australian routers are routinely probed for default credentials by automated scanners. Pick a strong passphrase, store it in a password manager, and move on.
Writing rules that suit your household
Most home firewalls follow a default-deny model: block everything, then allow specific exceptions. Start by listing what you genuinely need open. For most households, that is just outbound web browsing (ports 80 and 443), DNS (port 53), and the protocols your smart devices need. Everything else stays blocked by default.
When you do need to open a port, do it as narrowly as possible. If you want to access a security camera from your phone while at work, forward port 554 to the camera's static IP rather than putting the camera in the DMZ. Port forwarding should always target a specific internal IP, not a range, and ideally should be limited to the protocols you actually need. Universal Plug and Play is convenient but is also a known weak point exploited by malware. Unless you have a specific reason to enable it, switch it off.
If your household is a heavy streaming family, you'll want to make sure your firewall does not inadvertently block services like Netflix, Stan, Binge, or ABC iView. The audio and visual quality of those streams is partly down to clever encoding, and if you're curious about how sound design shapes immersive viewing, this sound design analysis is a fascinating tangent. For your firewall, simply permit outbound HTTPS and the relevant streaming ports.
Keeping the firewall healthy over time
A firewall is not a set-and-forget device. Firmware updates patch newly discovered vulnerabilities, and router vendors release them regularly, whether that's Telstra pushing monthly updates to its Smart Modems or ASUS rolling out quarterly security patches for its higher-end models. Enable automatic updates wherever possible, and check the vendor's support page every couple of months just to be sure you have not missed anything critical.
Review your firewall logs occasionally. Most home firewalls keep a buffer of blocked connection attempts, and a sudden spike from a single source IP often indicates someone is scanning your network. You can usually see this in the router's admin interface under a "Logs" or "Security" tab. If you see the same external IP trying thousands of connections, block it at the firewall level.
Audit your rules once or twice a year. Devices come and go, old rules accumulate, and a quarterly tidy-up keeps things clean. If you upgrade your NBN plan to something like Aussie Broadband's gigabit service, treat it as a trigger for a full firewall review.
For anyone thinking of turning this knowledge into a career, the Australian government regularly hires IT security specialists, and a polished cover letter helps. The team at E-Pragati has put together practical advice on tips for writing a cover letter for a government IT job that is well worth a read before you apply. Pair that with hands-on experience configuring a firewall at home, and you have a solid story to tell in an interview. For more guides, explainers, and reference material on digital governance, networking, and general tech topics, head over to E-Pragati and have a browse.
— get in touch
Have a question or want to reach out?