A firewall is a security system that monitors and controls incoming and outgoing network traffic based on security rules.
Firewall types
📮 Packet Filtering L3
Stateless · ACL
Inspects headers (IP, port, flags) — each packet in isolation.
- ✔ Very fast, low latency
- ✖ No context, spoofing possible
🧠 Stateful L3–L4
SPI · tracks connections
Keeps a state table — allows replies to outgoing requests.
- ✔ Smart, hides open ports
- ✖ Doesn't inspect payload
📄 Proxy L7
Application gateway
Acts as an intermediary — terminates and rewrites traffic.
- ✔ Deep content inspection, caching
- ✖ Slower, protocol-specific
🚀 NGFW L3–L7+
Next-Gen · DPI · IPS
Stateful + Proxy + IPS — identifies apps and users, inspects SSL.
- ✔ Sandboxing, threat prevention
- ✖ Expensive, needs updates
| Feature | Packet Filter | Stateful | Proxy | NGFW |
|---|---|---|---|---|
| OSI Layer | L3 (Network) | L3–L4 | L7 (App) | L3–L7 + sandbox |
| Payload inspection | ❌ No | ❌ No | ✅ Deep | ✅ Deep + SSL |
| State awareness | ❌ | ✅ Yes | ✅ (own) | ✅ Yes |
| Performance | ⚡ Highest | ⚡ High | 🐢 Lower | ⚡⚡ Moderate–High |
| Malware / IPS | ❌ | ❌ | ⚠️ Basic | ✅ IPS + Anti‑Malware |
| Main weakness | IP spoofing | blind to payload | complex, slow | cost & maintenance |