but to block all other traffic. Experience has shown that firewalls are
very frequently configured incorrectly, allowing unsafe access. Part of the
problem is that filtering rules can overlap in complex ways, making it
hard for a system administrator to correctly express the intended filtering.
A design principle that maximizes security is to configure a firewall to discard
all packets other than those that are explicitly allowed. Of course, this
means that some valid applications might be accidentally disabled; presumably
users of those applications eventually notice and ask the system
administrator to make the appropriate change.