Application-level gateway (proxy firewall)

A firewall that terminates each connection and relays it through a proxy for a specific application protocol, so it can inspect and filter content at OSI layer 7.

An application-level gateway, also called an application proxy or proxy firewall, is a firewall that works at the application layer, layer 7 of the OSI model. The client never connects directly to the server. It connects to the gateway, which terminates the session, examines the request with knowledge of the protocol (HTTP, SMTP or FTP, for example) and, if policy allows, opens a separate connection to the destination on the client’s behalf. NIST SP 800-41 Rev 1 describes application-proxy gateways as one of the firewall technologies.

Because it understands the protocol, the gateway can filter on content: commands, URLs, file types or malformed requests that a packet-filtering firewall or a stateful inspection firewall would let through. It also hides internal addresses, since outside hosts see only the proxy. The costs are performance, because every session is terminated and rebuilt, and coverage, because each protocol needs its own proxy. A circuit-level gateway relays sessions without reading application content. The gateway is commonly run on a hardened bastion host.

Exam relevance: a scenario is likely to ask which firewall type can inspect the content of a specific application protocol, or which one breaks the direct connection between client and server. Both point to the application-level gateway, and the trade-off to remember is deeper inspection at the cost of throughput.