


Deep-packet inspection is an improvement over traditional firewall technology, which only inspected a packet’s IP header to determine its source and destination. Deep-packet inspection, which inspects the data contained in packets.This is a key feature of next-generation firewalls: They can block traffic from certain applications, as well as maintain greater control over individual applications. Application awareness, or the ability to filter traffic and apply complex rules based on application (rather than just based on port).

Next-generation firewall specifications vary by provider, but they generally include some combination of the following features:
