Next-Generation Firewall (NGFW)

A firewall that adds application awareness, user identity and integrated intrusion prevention to stateful inspection, so policy can name applications rather than only ports.

A next-generation firewall builds on stateful inspection and adds several functions. The defining one is application awareness: it identifies the application in a flow from the traffic itself, not from the port number, so a rule can allow a business application while blocking a file-sharing tool that happens to use the same port. NGFWs commonly also tie traffic to user identity from a directory service, include intrusion prevention, apply threat intelligence feeds, and can decrypt and inspect TLS traffic where policy and privacy rules allow.

The NGFW sits at the end of the firewall generations that run from the stateless packet-filtering firewall, through stateful inspection and the proxy-based application-level gateway. It is often confused with two neighbours. A unified threat management appliance bundles similar functions, commonly for smaller sites. A web application firewall is narrower: it protects web applications against attacks carried in HTTP requests, such as injection, which a general-purpose NGFW is not designed to analyse in the same depth. Consolidation also concentrates risk in one device.

Exam relevance: a scenario that needs policy by application or by user, rather than by address and port, is likely to point to an NGFW. Candidates are expected to tell it apart from a WAF, which protects a web application rather than a network boundary.