Firewall service 202 also includes a non-policy level interface 210 at which an entity such as an application or service, denoted generically as program 211, may contact firewall service with requests to dynamically update policy rules, as shown in FIG. 2B. Such requests may include requests to open or close ports, requests to update network resource addresses with which communication is allowed,