Every packet entering the system is tagged as part of a Zone, and filtered according to the rules of that zone. The classification and (ordering of classification) is explained on the Technical Details page.
Firewall works in a 'Deny by Default' mode, and it removes the previous need to blacklist networks, as they are blocked by default.
However, enabling Responsive Firewall exposes selected signalling to the internet. You may add specific networks or hosts to the Blacklist page to ensure that they can not use Responsive Firewall.