Next Gen Firewall
What is a Next Gen Firewall (NGFW)?

A next generation firewall (NGFW) permits or blocks traffic between networks. Next generation firewalls add advanced capabilities like application-level packet inspection and intrusion prevention to traditional packet-filtering network firewall capabilities.

Cropped shot of an unrecognizable male police officer using his laptop while out on patrol.
  • Next generation firewalls explained
  • What are next generation firewall features?
  • What are the benefits of next generation firewalls?
  • What’s the difference between next gen firewalls and unified threat management?
  • How a next generation firewall works
  • What is the best next generation firewall?
Next generation firewalls explained

Next generation firewalls explained

A next generation firewall can also be called a next gen firewall, nextgen firewall, or nexgen firewall. Network firewalls act by analyzing traffic between networks and allowing or denying passage of traffic based on defined firewall policies relative to traffic characteristics. Next generation firewalls can ingest information from other systems as well as inspect more characteristics of traffic to enforce firewall policies at higher order Transmission Control Protocol/Internet Protocol (TCP/IP) communication layers than a traditional firewall. The additional information and deeper level of inspection utilized by next gen firewalls enables them to identify and prevent attacks.

Next generation firewalls vs. traditional firewalls

Capability
Traditional firewall
Next generation firewall
Advantages of next generation firewall

Inspection

Stateless

Stateful

Blocks traffic that deviates from expected norm compared to established connections

Visibility

Rudimentary, only lower TCP/IP layers

Deep, includes all TCP/IP layers

Enables more granular and robust analysis of traffic

Services

Basic

Comprehensive

Includes UTM services such as antivirus, content filtering, IDS/IPS, and logging in addition to packet filtering

Protection

Limited

Enhanced

Identifies, prevents, and reports a broader variety of attacks

HPE Aruba Networking EdgeConnect SD-WAN

Power branch, WAN and security with a secure SD-WAN as the foundational component for architecting a secure access service edge (SASE).

Related topics

Zero Trust Security

SSE (Security Service Edge)

Network Security

Dynamic Segmentation