Next-Generation Firewalls (NGFWs) go beyond traditional packet filtering. They combine standard firewall features with:
- Deep packet inspection
- Application identification
- User identity awareness
- Integrated intrusion prevention
- SSL/TLS decryption
Traditional firewalls see port as HTTPS. An NGFW identifies the actual application. Is it legitimate banking or malware using HTTPS to hide? The NGFW knows the difference.