Home/Next-Generation Firewall

Advanced protection

Firewall decisions with the full context attached.

Application-aware inspection, intrusion prevention and granular policy — for organisations that need to know what traffic is, not only where it came from.

  • Policy by application, user or group
  • Intrusion prevention and deeper inspection
  • Detailed visibility of network activity
Conventional firewall compared with a next-generation firewallA conventional firewall decides using source and destination, port number and protocol. A next-generation firewall adds context: the application in use, content and behaviour, intrusion prevention, and policy by user or group.CONVENTIONAL FIREWALLDecides on address and portSource and destinationPort numberProtocolLIMITED VIEW OF WHAT THE TRAFFIC ISNEXT-GENERATION FIREWALLAdds context to the decisionApplication in useContent and behaviourIntrusion preventionPolicy by user or group
What a conventional firewall sees, and what an NGFW adds

The difference

Same job. Considerably more information.

A conventional firewall asks whether a connection is permitted. A next-generation firewall asks what the connection is actually doing.

Conventional

Address, port, protocol

Useful, fast and still the foundation of network protection. The limitation is that many different services share the same ports, so a rule that permits one thing often permits several others by accident.

  • Allows or blocks by source and destination
  • Works at the level of connections and sessions
  • Limited insight into what the traffic contains

Next-generation

Application, behaviour, identity

Recognises the application in use and inspects traffic more deeply, so policy can permit exactly what is needed and decline the rest — even when both use the same port.

  • Identifies the application, not just the port
  • Inspects traffic for known attack patterns
  • Applies policy by user, group or site

Capabilities

What the additional context makes possible.

Application control

Permit the applications your work depends on and restrict the ones it does not, with rules that recognise the difference.

Advanced traffic inspection

Deeper examination of traffic crossing the boundary, so decisions rest on more than the header of a connection.

Intrusion prevention

Detection of traffic patterns associated with known attack techniques, with action taken according to policy.

Threat detection

Signals from traffic behaviour compared against known indicators, surfaced for review rather than buried in a log file.

Policy management

Rules organised by application, group or site, changed centrally and applied consistently.

Network visibility

A clearer picture of what is actually running on the network — often the first genuinely useful outcome.

How a decision is made

Four questions, asked in order, on every connection.

Deep inspection is easier to trust when the sequence is visible. Traffic is observed, compared against policy and known patterns, acted on, and the result is recorded for review.

That last step is what turns a security control into something you can audit: a decision that can be examined, explained and corrected if the rule behind it was wrong.

Sizing note

Inspection depth, throughput and available features depend on the configuration selected for your environment.

Automated security analysis workflowA four-stage workflow: observe traffic and connection activity, compare it against known patterns and policy rules, decide whether to allow, limit or block it, and record the event for later review.ObserveTRAFFIC AND CONNECTIONACTIVITY01CompareKNOWN PATTERNS ANDPOLICY RULES02DecideALLOW, LIMIT ORBLOCK03RecordEVENT HISTORY FORREVIEW04RUNS CONTINUOUSLY · NO MANUAL RULE-WRITING REQUIRED FOR HOME PLANS
Observe, compare, decide, record

Is it the right fit?

Worth being straightforward about this one.

A good fit when

  • Different teams need different levels of access
  • Applications matter more than ports in your policy
  • You need intrusion prevention as part of the boundary
  • Activity records are needed for review or reporting

Probably not yet when

  • A single site with straightforward requirements
  • Blanket allow or block rules already cover your needs
  • You are protecting a household rather than an organisation
  • Nobody is available to act on the additional detail

FAQ

Next-generation firewall questions.

What makes a firewall 'next-generation'?

A conventional firewall decides using addresses, ports and protocols. A next-generation firewall adds context — which application is in use, how the traffic behaves, and which user or group it belongs to — and can act on that context.

Do we need one, or is a standard firewall enough?

It depends on how specific your policy needs to be. If allowing or blocking whole ports covers your requirements, a standard configuration may be sufficient. If you need to permit one application while restricting another that uses the same port, that is the case for NGFW.

What is intrusion prevention?

Inspection that looks for traffic patterns associated with known attack techniques and acts on them according to policy — rather than only checking whether a connection is permitted in principle.

Does more inspection mean slower networks?

Deeper inspection does more work per connection, so sizing matters. Configurations are matched to your traffic levels, and actual performance depends on your environment, connectivity and the policy in place.

Is this available for home networks?

Next-generation capabilities are aimed at organisations that need granular control. Households are generally better served by the home firewall service, which applies the same protective idea with settings suited to a home.

Can we start simple and add capability later?

Yes. Many organisations begin with a business firewall configuration and move to next-generation capabilities as their policy requirements become more specific. Options vary by configuration.

Next step

Find out whether next-generation is the right step.

Describe what you need policy to distinguish between, and we will tell you honestly whether a standard configuration would already cover it.