Four generations
- packet filtering judges every packet independently by addresses and port; it does not remember who opened the connection.
- Stateful inspection keeps a state table. Return traffic is allowed only when it matches an existing connection entry.
- An application gateway or proxy firewall terminates TCP on both sides and inspects the application protocol — deep inspection at a performance cost.
- An adds application control and SSL inspection: it considers not just addresses and ports, but what is actually running.
IDS, IPS and FortiGate
An detects and alerts, usually out of path; an sits inline and can block. FortiGate combines firewall, VPN and IPS, surrounded by FortiManager, , , FortiAP and FortiSandbox on . 1–8 is a historical track; the current certification program uses new names.
FortiOS 7.4.x practice
Display the state table, find your connection after browsing, then run a focused sniffer.
Write a stateless ACL that permits DNS replies to high ports, then explain why a stateful firewall needs no broad return rule: the state table already authorizes the reply.
Risks and mitigation
- An without updates or an equivalent feed is yesterday's firewall.
- An without a response team is only a warning; use an inline or a backed by a response process.
- Document which capabilities require licensing and activation. An does not replace Event IDs or forged ticket detection.
- Related topics: the lesson and the network view of attacks.