This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

NGFW (next-generation firewall)

Information Security

NGFW is a next-generation firewall with IPS, application control and deep packet inspection functions to protect against modern threats.

What is an NGFW

NGFW (Next-Generation Firewall) is a next-generation firewall that combines the functions of a traditional firewall with deep packet inspection (DPI), an intrusion prevention system (IPS), application control and other advanced capabilities. Unlike classic firewalls, NGFW analyzes traffic at all levels of the OSI model, including the application layer, which allows identifying specific applications and blocking threats regardless of the ports and protocols used.

NGFW — next-generation firewall: features and benefits NGFW architecture: DPI (deep packet inspection), IPS (intrusion prevention), application control, URL filtering, SSL/TLS inspection and antivirus scanning. Unlike a regular firewall, it analyzes traffic at all levels. NGFW architecture: next-generation firewall Incoming traffic Internet NGFW DPI — deep packet inspection IPS — intrusion prevention Application control Safe traffic Internal network NGFW features URL and web content filtering SSL/TLS inspection Antivirus scanning NGFW vs Firewall ✅ Analysis at all levels ✅ Application identification ✅ Built-in IPS ✅ Antivirus ✅ SSL inspection ❌ Regular firewall: packet filtering only and state tracking NGFW architecture: deep traffic analysis with protection against modern threats
NGFW (next-generation firewall) — term diagram

Key functions

  • Deep packet inspection (DPI) — analysis of traffic content to detect malware.
  • Intrusion prevention system (IPS) — real-time detection and blocking of attacks.
  • Application control — identification of applications regardless of port or protocol.
  • URL filtering and antivirus inspection at the gateway level.

NGFW applications

NGFW is used to protect the network perimeter, segment internal networks and protect data centers. In government information systems, the use of NGFW must comply with the requirements of the FSTEC of Russia. Installation services for NGFW include developing security policies, configuring filtering rules and integrating with SIEM and SOC.

Conclusion

NGFW is an evolutionary development of firewalls, necessary for protection against modern cyber threats.

Key NGFW functions

Next-generation firewalls (NGFW) combine traditional firewall functions with advanced capabilities: application-layer packet inspection (Deep Packet Inspection), application control regardless of ports and protocols, an intrusion prevention system (IPS), antivirus traffic inspection, URL and web content filtering, and DDoS protection. NGFW identifies applications by signatures and behavioral analysis rather than just ports, which allows blocking the use of unwanted applications (messengers, torrents, P2P). SSL/TLS inspection technology decrypts HTTPS traffic for analysis, checks it for threats and re-encrypts it before sending to the recipient — this is critical because more than 90% of modern internet traffic is encrypted.

Architecture and network placement

NGFW is placed at the network edge (perimeter), between internal segments (DMZ, internal network, guest Wi-Fi) and in front of data centers. A typical architecture includes several security zones: external (WAN), internal (LAN), and a demilitarized zone (DMZ) for public servers. Each zone has its own access policies. When choosing an NGFW, throughput is taken into account: for an office with 500 users, a 1-2 Gbps device is sufficient; for data centers, solutions with 10+ Gbps and hardware acceleration are required. Modern NGFWs support active-active cluster operation for fault tolerance and load balancing, which ensures continuity of protection even if one device fails.

Integration of NGFW with other security tools creates a layered security system. NGFW sends events and logs to a SIEM system for centralized monitoring, interacts with SOAR systems for automated incident response, and synchronizes with vulnerability management systems to block traffic to compromised nodes. Modern NGFWs support integration with sandboxes for analyzing suspicious files in an isolated environment before sending them to the recipient. When designing a network architecture, it is important to correctly choose the NGFW operating mode: L2 bridge (transparent mode without changing IP addressing), L3 routing (with NAT and routing between zones) or a hybrid mode. In Russian conditions, NGFW must also support blocking according to the unified register of prohibited sites and integration with the TSPU system.

The choice of NGFW depends on the network scale, the number of users and the required functions. For small and medium-sized enterprises (up to 500 users), integrated solutions that combine NGFW, switching and Wi-Fi in one device are suitable. For large organizations and data centers, high-performance NGFWs with hardware acceleration of cryptographic operations and cluster support are required. When choosing, the following are taken into account: throughput with security services enabled (IPS, antivirus, DLP), the number of concurrent sessions, SSL/TLS inspection support, and compatibility with Russian CIPF tools for organizing VPN channels. Regular updating of IPS and antivirus signature databases is critical for protection against new threats. It is also recommended to use a centralized NGFW management system for a unified security policy on all devices.

Frequently asked questions

What is an NGFW (next-generation firewall)?

NGFW (Next-Generation Firewall) is a next-generation firewall that combines the functions of a traditional firewall with deep packet inspection (DPI), an intrusion prevention system (IPS) and application control. Unlike a classic firewall, it analyzes traffic at the application layer and can identify applications and block threats regardless of ports and protocols.

How does an NGFW (next-generation firewall) work?

An NGFW inspects traffic at all levels of the OSI model. In addition to traditional packet filtering, it performs deep packet inspection (DPI), identifies applications by signatures and behavioral analysis, detects and blocks attacks in real time with an intrusion prevention system (IPS), filters URLs and scans traffic for malware.

Where is an NGFW (next-generation firewall) applied?

NGFW is used to protect the network perimeter, segment internal networks and protect data centers. It is deployed at the boundary between the corporate network and the Internet, as well as in front of segments with confidential data. In government information systems, the use of NGFW must comply with the requirements of the FSTEC of Russia.

What advantages does an NGFW (next-generation firewall) provide?

NGFW provides a higher level of protection compared to classic firewalls: deep packet inspection (DPI), an intrusion prevention system (IPS), application control regardless of ports and protocols, antivirus traffic inspection, URL and web content filtering, and DDoS protection. This allows detecting and blocking modern threats that traditional firewalls miss.

What are the NGFW (next-generation firewall) requirements in Russia?

The requirements for NGFW in Russia depend on the type of facility being protected. In government information systems, the use of NGFW must comply with the requirements of the FSTEC of Russia. For critical information infrastructure (CII) facilities, the requirements of 187-FZ apply. It is recommended to use certified solutions and integrate NGFW with SIEM and SOC.

How is an NGFW (next-generation firewall) different from analogues?

NGFW differs from a traditional firewall by its ability to inspect traffic at the application layer. A classic firewall filters packets by addresses and ports, while NGFW performs deep packet inspection, identifies applications by signatures and behavior, and combines IPS, antivirus and URL filtering in one device. This makes it more effective against modern threats.

How to implement an NGFW (next-generation firewall) in an organization?

To implement an NGFW in an organization, you need to: 1) choose a solution that meets the security requirements, 2) develop a security policy and filtering rules, 3) deploy the NGFW at the network boundary and configure traffic segmentation, 4) integrate it with SIEM and SOC for monitoring. The installation service includes NGFW deployment and configuration.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate ngfw (next-generation firewall) into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm