What is a next-generation firewall (NGFW)? Definition from SearchSecurity (2024)

By

What is a next-generation firewall (NGFW)?

A next-generation firewall (NGFW) is part of the third generation of firewall technology that can be implemented in hardware or software. It is capable of detecting and blocking sophisticated attacks by enforcing security policies at the application, port and protocol levels.

NGFWs typically feature advanced functions including:

  • application awareness;
  • integrated intrusion prevention systems (IPSes);
  • identity awareness -- user and group control;
  • bridged and routed modes; and
  • the ability to use external intelligence sources.

Of these offerings, most next-generation firewalls integrate at least three basic functions: enterprise firewall capabilities, an IPS and application control.

Like the introduction of stateful inspection in traditional firewalls, NGFWs bring additional context to the firewall's decision-making process. They provide it with the ability to understand the details of web application traffic passing through it and to take action to block traffic that might exploit vulnerabilities.

What is a next-generation firewall (NGFW)? Definition from SearchSecurity (1)

Next-generation firewall features

NGFWs combine many of the capabilities of traditional firewalls -- including packet filtering, network address translation (NAT) and port address translation (PAT), URL blocking, and virtual private networks (VPNs) -- with quality of service (QoS) functionality and other features not found in traditional firewalls. These include intrusion prevention, SSL and SSH inspection, deep-packet inspection, and reputation-based malware detection, as well as application awareness.

These application-specific capabilities are meant to thwart the growing number of application attacks taking place at Layers 4-7 of the OSI network stack.

Benefits of next-generation firewalls

The different features of next-generation firewalls combine to create unique benefits for users. NGFWs are often able to block malware before it enters a network, something that not possible previously.

NGFWs are also better equipped to address advanced persistent threats (APTs) because they can be integrated with threat intelligence services. NGFWs also can offer a low-cost option for companies trying to improve basic device security through the use of application awareness, inspection services, protection systems and awareness tools.

Next-generation firewall vs. traditional firewall

While both NGFW and traditional firewalls aim to protect an organization's network and data assets, they also have several differences.

The main similarities include static packet filtering to block packets at the point of interface to network traffic. They also both have the capability to provide stateful packet inspection, network and port address translations, and both can set up VPN connections.

One of the most important differences between traditional and next-generation firewalls is that NGFWs offer deep-packet inspection that goes beyond simple port and protocol inspection by inspecting the data carried in network packets. Other key differences are that NGFWs add application-level inspection, intrusion prevention and the ability to act on data provided by threat intelligence services.

NGFWs extend the traditional firewall functionality of NAT, PAT and VPN support to operate both in routed mode -- in which the firewall behaves as a router -- and in transparent mode -- in which the firewall behaves like a bump in the wire when it scans packets -- while also integrating new threat management technologies.

This was last updated in October 2021

Continue Reading About next-generation firewall (NGFW)

Related Terms

What is an endpoint protection platform (EPP)?
An endpoint protection platform (EPP) is a security technology that safeguards endpoint devices.Seecompletedefinition
What is endpoint security? How does it work?
Endpoint security is the protection of endpoint devices against cybersecurity threats.Seecompletedefinition
What is network detection and response (NDR)?
Network detection and response (NDR) technology continuously scrutinizes network traffic to identify suspicious activity and ...Seecompletedefinition

Dig Deeper on Network security

What is a next-generation firewall (NGFW)? Definition from SearchSecurity (2024)
Top Articles
Control notifications on Android - Android Help
Tips to park your manual transmission vehicle - Manual Driving School
11 beste sites voor Word-labelsjablonen (2024) [GRATIS]
Friskies Tender And Crunchy Recall
Fort Morgan Hometown Takeover Map
Umbc Baseball Camp
Swimgs Yuzzle Wuzzle Yups Wits Sadie Plant Tune 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Autumns Cow Dog Pig Tim Cook’s Birthday Buff Work It Out Wombats Pineview Playtime Chronicles Day Of The Dead The Alpha Baa Baa Twinkle
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Craigslist Pets Longview Tx
Restored Republic January 20 2023
Missed Connections Inland Empire
Autobell Car Wash Hickory Reviews
Kent And Pelczar Obituaries
Www.paystubportal.com/7-11 Login
Oriellys St James Mn
Valentina Gonzalez Leak
6th gen chevy camaro forumCamaro ZL1 Z28 SS LT Camaro forums, news, blog, reviews, wallpapers, pricing – Camaro5.com
Dc Gas Login
Hell's Kitchen Valley Center Photos Menu
Rachel Griffin Bikini
Conan Exiles: Nahrung und Trinken finden und herstellen
Forum Phun Extra
How To Level Up Roc Rlcraft
Caledonia - a simple love song to Scotland
Gayla Glenn Harris County Texas Update
What Channel Is Court Tv On Verizon Fios
Tu Pulga Online Utah
Plaza Bonita Sycuan Bus Schedule
UMvC3 OTT: Welcome to 2013!
Craigslist Roseburg Oregon Free Stuff
T Mobile Rival Crossword Clue
Jailfunds Send Message
Vivification Harry Potter
Federal Express Drop Off Center Near Me
91 Octane Gas Prices Near Me
Bursar.okstate.edu
Mrstryst
Blackstone Launchpad Ucf
2012 Street Glide Blue Book Value
آدرس جدید بند موویز
Puffco Peak 3 Red Flashes
Bbc Gahuzamiryango Live
Kelly Ripa Necklace 2022
Albertville Memorial Funeral Home Obituaries
Is The Nun Based On a True Story?
Puretalkusa.com/Amac
Tsbarbiespanishxxl
Suffix With Pent Crossword Clue
Henry Ford’s Greatest Achievements and Inventions - World History Edu
Vindy.com Obituaries
Makes A Successful Catch Maybe Crossword Clue
Craigslist.raleigh
Latest Posts
Article information

Author: Van Hayes

Last Updated:

Views: 5548

Rating: 4.6 / 5 (46 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Van Hayes

Birthday: 1994-06-07

Address: 2004 Kling Rapid, New Destiny, MT 64658-2367

Phone: +512425013758

Job: National Farming Director

Hobby: Reading, Polo, Genealogy, amateur radio, Scouting, Stand-up comedy, Cryptography

Introduction: My name is Van Hayes, I am a thankful, friendly, smiling, calm, powerful, fine, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.