Skip to main content
AD Academy
Network security: Fortinet
Beginner17 minLast updated: Topic 2 of 14

Firewall evolution — from stateless to NGFW

State tables, proxy firewalls, IDS/IPS and FortiGate.

Not read

What you will learn here

  • Four generations
  • IDS, IPS and FortiGate
  • FortiOS 7.4.x practice

Worth reading first:Infrastructure security devices

Four generations

  • packet filtering judges every packet independently by addresses and port; it does not remember who opened the connection.
  • Stateful inspection keeps a state table. Return traffic is allowed only when it matches an existing connection entry.
  • An application gateway or proxy firewall terminates TCP on both sides and inspects the application protocol — deep inspection at a performance cost.
  • An adds application control and SSL inspection: it considers not just addresses and ports, but what is actually running.

IDS, IPS and FortiGate

An detects and alerts, usually out of path; an sits inline and can block. FortiGate combines firewall, VPN and IPS, surrounded by FortiManager, , , FortiAP and FortiSandbox on . 1–8 is a historical track; the current certification program uses new names.

FortiOS 7.4.x practice

Display the state table, find your connection after browsing, then run a focused sniffer.

diagnose firewall session list | head -30
diagnose sniffer packet any "host 10.0.0.50 and port 443" 4
bash

Write a stateless ACL that permits DNS replies to high ports, then explain why a stateful firewall needs no broad return rule: the state table already authorizes the reply.

Risks and mitigation

  • An without updates or an equivalent feed is yesterday's firewall.
  • An without a response team is only a warning; use an inline or a backed by a response process.
  • Document which capabilities require licensing and activation. An does not replace Event IDs or forged ticket detection.
  • Related topics: the lesson and the network view of attacks.

Check yourself

What is the fundamental difference between stateless and stateful filtering?

Why does stateful inspection solve the return-traffic problem?

What is the difference between IDS and IPS?

What distinguishes an NGFW?

Was this page helpful?