Application control
Permit the applications your work depends on and restrict the ones it does not, with rules that recognise the difference.
Home/Next-Generation Firewall
Advanced protection
Application-aware inspection, intrusion prevention and granular policy — for organisations that need to know what traffic is, not only where it came from.
The difference
A conventional firewall asks whether a connection is permitted. A next-generation firewall asks what the connection is actually doing.
Conventional
Useful, fast and still the foundation of network protection. The limitation is that many different services share the same ports, so a rule that permits one thing often permits several others by accident.
Next-generation
Recognises the application in use and inspects traffic more deeply, so policy can permit exactly what is needed and decline the rest — even when both use the same port.
Capabilities
Permit the applications your work depends on and restrict the ones it does not, with rules that recognise the difference.
Deeper examination of traffic crossing the boundary, so decisions rest on more than the header of a connection.
Detection of traffic patterns associated with known attack techniques, with action taken according to policy.
Signals from traffic behaviour compared against known indicators, surfaced for review rather than buried in a log file.
Rules organised by application, group or site, changed centrally and applied consistently.
A clearer picture of what is actually running on the network — often the first genuinely useful outcome.
How a decision is made
Deep inspection is easier to trust when the sequence is visible. Traffic is observed, compared against policy and known patterns, acted on, and the result is recorded for review.
That last step is what turns a security control into something you can audit: a decision that can be examined, explained and corrected if the rule behind it was wrong.
Inspection depth, throughput and available features depend on the configuration selected for your environment.
Is it the right fit?
FAQ
A conventional firewall decides using addresses, ports and protocols. A next-generation firewall adds context — which application is in use, how the traffic behaves, and which user or group it belongs to — and can act on that context.
It depends on how specific your policy needs to be. If allowing or blocking whole ports covers your requirements, a standard configuration may be sufficient. If you need to permit one application while restricting another that uses the same port, that is the case for NGFW.
Inspection that looks for traffic patterns associated with known attack techniques and acts on them according to policy — rather than only checking whether a connection is permitted in principle.
Deeper inspection does more work per connection, so sizing matters. Configurations are matched to your traffic levels, and actual performance depends on your environment, connectivity and the policy in place.
Next-generation capabilities are aimed at organisations that need granular control. Households are generally better served by the home firewall service, which applies the same protective idea with settings suited to a home.
Yes. Many organisations begin with a business firewall configuration and move to next-generation capabilities as their policy requirements become more specific. Options vary by configuration.
Next step
Describe what you need policy to distinguish between, and we will tell you honestly whether a standard configuration would already cover it.