What the provider router actually does – and where it stops
The router that comes with an internet connection includes a firewall function that filters incoming traffic by address and port and blocks unsolicited connections from outside. For a single flat network, where all devices are allowed to trust each other, this protects against the most obvious external attacks.
What most provider routers cannot do is control traffic between several internal network zones – they are built for one network, not several separated zones with their own rules. Checking which application actually sits behind a connection, or detecting unusual patterns in traffic, is also usually outside their scope. That is not a limitation of cheap hardware; it reflects what a provider router is built for: providing internet access, not running a security architecture.
- Filters incoming traffic by address and port, usually without application detection
- Typically builds a single flat network, not separated security zones
- Configured through a simple web interface, designed for households and very small offices