Stateful inspection firewall
A firewall that records each connection in a state table and judges packets in the context of that connection, so replies to permitted sessions pass without separate rules.
A stateful inspection firewall remembers the connections passing through it. When a permitted session opens, the firewall records it in a state table: the source and destination addresses, ports, protocol and, for TCP, where the connection sits in its lifecycle. Later packets are checked against that record, so a reply belonging to an established session is admitted, while an unsolicited packet that merely claims to be a reply is dropped. NIST SP 800-41 Rev. 1, the guide to firewalls and firewall policy, describes stateful inspection as an improvement on packet filtering. For connectionless UDP traffic, the firewall commonly keeps a pseudo-state that expires after a timeout.
A stateless packet-filtering firewall, by contrast, judges each packet alone against its rules, so it needs broad rules to let replies back in. A stateful firewall still works mainly at the network and transport layers; inspecting application content is the work of an application-level gateway or a next-generation firewall. The state table is itself a finite resource, which a SYN flood can exhaust.
Exam relevance: a scenario is likely to describe a firewall that admits return traffic only for sessions started from inside, which points to stateful inspection. Candidates are expected to place it between stateless filtering and application-layer proxying.