Traffic Simulator

Stateful firewall and NGFW inspection

One session, two decision models: port-based filtering versus context-aware inspection.

Stateful Firewall

L3 and L4 checks decide only from addressing and transport context.

IP header (L3) Source and destination routing context
10.0.1.55
dst: 0.0.0.0
Transport (L4) Port and session state
TCP / 443
ESTABLISHED

Payload encrypted

No Layer 7 visibility into the actual application or threat.

Next-Gen Firewall

App, user, content, and threat context reshape the final policy decision.

Session context Flow tuple and baseline state tracking
0.0.0.0:443
TCP session established
App-ID Fingerprint the real application inside port 443
pending...
User-ID Map the session back to a person or group
unknown
Content-ID URL category and threat verdict
--- ---