Stateful inspection has largely replaced an older technology, static packet filtering. In static packet filtering, only the headers of packets are checked -- which means that an attacker can sometimes get information through the firewall simply by indicating "reply" in the header. Stateful inspection, on the other hand, analyzes packets down to the application layer.

In Firewall Policies and VPN Configurations, 2006. Pros. Stateful inspection firewalls are the best balance between the performance of a packet filter and the security of an application proxy. There’s a wide selection of these firewalls available and they have few, if any drawbacks. Networking Standard. A stateful inspection firewall is the de facto standard for network protection at this time.

A next-generation firewall (NGFW) is a network security device that provides capabilities beyond a traditional, stateful firewall. While a traditional firewall typically provides stateful inspection of incoming and outgoing network traffic, a next-generation firewall includes additional features like application awareness and control, integrated intrusion prevention, and cloud-delivered threat