Yes, you are correct. but I’m not talking about a built-in Windoz firewall. I run a stand alone pfSense firewall with a default deny policy. Nothing gets in unless solicited and nothing goes out, except on ports 80 and 443 without my express approval. Beyond that, I must white list the individual server, or network, before it can be accessed.