not how a "propper" firewall works
the basic principle is you start by blocking everything ...
then open ports to let things out
80 - for your browser etc
http://www.chebucto.ns.ca/~rakerman/port-table .html
the updated firewall is generally part of a software package
avira, kaspersky, zone alarm
and as vhg says ... they also tend to prevent you switching the windows one on while they are installed
the packaged walls tend to be more useful as part of a virus/trojan kit because they have application filtering to stop new stuff just broadcasting from your machine
.... on the router it's called port forwarding ... so you can say
all ftp traffic goes to xxxx
or block any traffic on port 2356
the updateable firewall will also use your hosts file
http://www.abelhadigital.com/
so you can do it all ... but it's lumpy - far better to consider an internet security suite