What is a next-generation firewall (NGFW)?

A next-generation firewall (NGFW) is a network security device that combines traditional stateful firewall functions with application awareness and control, integrated intrusion prevention, advanced threat detection, and user identity awareness.

Like a traditional firewall, an NGFW tracks connection state and filters traffic on the 5-tuple (source and destination IP, source and destination port, and protocol). What sets it apart is inspection at the application layer: an NGFW identifies the specific applications and users behind the traffic and blocks modern threats that a traditional firewall, which stops at the 5-tuple and connection state, cannot see.

Next-generation firewall overview

A traditional firewall provides stateful inspection of network traffic, allowing or blocking traffic based on IP, port, and protocol. A next-generation firewall does this and more. According to Gartner, which defined the NGFW category, a next-generation firewall should include:

  • Application control — see and block risky applications, not just ports and protocols
  • Integrated intrusion prevention (IPS) — detect and stop known and emerging exploits
  • Advanced malware protection — analyze file behavior to catch threats that evade other defenses
  • User and identity awareness — apply policy based on who the user is, not just IP address
  • TLS/SSL decryption — decrypt and inspect encrypted traffic where modern threats hide
  • Threat intelligence integration — use current intelligence to stop emerging threats

What should I look for in a next-generation firewall?

The best next-generation firewalls deliver five core benefits to organizations, from SMBs to enterprises. Make sure your NGFW delivers:

Breach prevention and advanced security

The number-1 job of a firewall should be to prevent breaches and keep your organization safe. But since preventive measures will never be 100% effective, your firewall should also have advanced capabilities to quickly detect advanced malware if it evades your front-line defenses. Invest in a firewall with the following capabilities:

  • Prevention to stop attacks before they get inside
  • A best-of-breed next-generation IPS built in to spot stealthy threats and stop them fast
  • URL filtering to enforce policies on hundreds of millions of URLs
  • Built-in sandboxing and Advanced Malware Protection that continuously analyzes file behavior to quickly detect and eliminate threats
  • A world-class threat intelligence organization that provides the firewall with the latest intelligence to stop emerging threats

Comprehensive network visibility

You can't protect against what you can't see. You need to monitor what is happening on your network at all times so you can spot bad behavior and stop it fast. Your firewall should provide a holistic view of activity and full contextual awareness to see:

  • Threat activity across users, hosts, networks, and devices
  • Where and when a threat originated, where else it has been across your extended network, and what it is doing now
  • Active applications and websites
  • Communications between virtual machines, file transfers, and more

Flexible management and deployment options

Whether you are a small to medium-sized business or a large enterprise, your firewall should meet your unique requirements:

  • Management for every use case: Choose from an on-box manager or centralized management across all appliances
  • Deploy on-premises or in the cloud using a virtual firewall
  • Customize with features that meet your needs: Simply turn on subscriptions to get advanced capabilities
  • Choose from a wide range of throughput speeds

Fastest time to detection

The current industry standard time to detect a threat is between 100 to 200 days; that is far too long. A next-generation firewall should be able to:

  • Detect threats in seconds
  • Detect the presence of a successful breach within hours or minutes
  • Prioritize alerts so you can take swift and precise action to eliminate threats
  • Make your life easier by deploying consistent policy that's easy to maintain, with automatic enforcement across all the different facets of your organization

Automation and product integrations

Your next-generation firewall should not be a siloed tool. It should communicate and work together with the rest of your security architecture. Choose a firewall that:

  • Seamlessly integrates with other tools from the same vendor
  • Automatically shares threat information, event data, policy, and contextual information with email, web, endpoint, and network security tools
  • Automates security tasks like impact assessment, policy management and tuning, and user identification

Common questions about next-generation firewalls

A next-generation firewall is a network security device that adds application awareness, integrated intrusion prevention, advanced threat detection, and user identity awareness to a traditional firewall. It identifies applications by analyzing the packets they generate across network layers — not just ports and protocols — to detect and block threats that traditional firewalls miss.

A traditional firewall filters traffic by IP, port, and protocol. An NGFW does that and also inspects the application and user behind the traffic, runs integrated intrusion prevention, and applies threat intelligence to block modern attacks.

At minimum, an NGFW should include application control, integrated intrusion prevention, advanced malware protection, user and identity awareness, TLS/SSL decryption and inspection, and threat intelligence integration. Most organizations also weigh management options, deployment flexibility, and how well the firewall integrates with their existing security tools.

Unified threat management (UTM) bundles multiple security functions into one appliance, often aimed at small and midsize organizations and simplicity. An NGFW emphasizes deep, integrated application-layer inspection and intrusion prevention and is built to scale to enterprise performance and policy needs; the categories overlap, but NGFWs are typically positioned for more demanding environments.

In most cases, no. A next-generation firewall includes integrated intrusion prevention, so the IPS function is built in rather than deployed as a separate device. Some organizations still run a dedicated IPS for specialized or high-throughput segments, but for most networks the NGFW's integrated IPS covers the need.

Decide which Cisco firewall is right for you

Answer the following questions to find out which offering is the best fit for your needs.

Start the guide