- Checks packets for source/destination IP, port, and protocol.
- Lightweight but limited context awareness.
- Monitors state of active connections.
- Makes decisions based on connection context.
- Intercepts traffic between client and server.
- Can filter at application layer.
- Combines traditional firewall with features like IPS, deep packet inspection, application control.