# What is a Next-Generation Firewall (NGFW)?

> A next-generation firewall (NGFW) is an industry label for a firewall that combines traditional traffic control with deeper application-aware inspection and additional security functions.

- Canonical URL: https://yellowcube.eu/glossary/next-generation-firewall/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Common capabilities include application identification, user or identity context, intrusion prevention, web filtering, malware analysis, encrypted-traffic inspection, and threat-intelligence integration.

There is no universal technical threshold that makes a firewall “next-generation.” Products differ in inspection depth, supported protocols, identity integration, policy model, performance, cloud coverage, and how optional subscriptions affect protection. Evaluation should therefore use required capabilities and tested outcomes rather than the label alone.

### Key points

- **Potential value:** Apply more specific policy than addresses and ports alone and consolidate related inspection functions.
- **Key design questions:** Which traffic is visible, which protocols are decoded, how identities are mapped, and what happens when inspection fails?
- **Operational needs:** Rule governance, signature and software updates, tuning, logging, validated capacity, and certificate lifecycle management where TLS decryption is deployed.
- **Important limitation:** Encrypted traffic, evasive protocols, unsupported applications, privacy constraints, and performance trade-offs can reduce inspection.

### Related terms

[Firewall](<https://yellowcube.eu/glossary/firewall/>) · [Intrusion prevention system (IPS)](<https://yellowcube.eu/glossary/intrusion-prevention-system/>) · [Transport Layer Security (TLS) inspection](<https://yellowcube.eu/glossary/transport-layer-security-inspection/>) · [Secure access service edge (SASE)](<https://yellowcube.eu/glossary/secure-access-service-edge/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Proxy firewall](<https://yellowcube.eu/glossary/proxy-firewall/>) · [Unified threat management (UTM)](<https://yellowcube.eu/glossary/unified-threat-management/>)

### Sources

[NIST SP 800-41r1: Guidelines on Firewalls and Firewall Policy](https://csrc.nist.gov/pubs/sp/800/41/r1/final) · [NIST SP 800-215: Secure Enterprise Network Landscape](https://csrc.nist.gov/pubs/sp/800/215/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

