Comparison Between Stateful Inspection Firewall and Next Generation Firewall in LAN and WAN Environments

Authors

  • Aws Abdulkareem DUC Author

DOI:

https://doi.org/10.65204/djes.v3i3.848

Abstract

 

Stateful inspection firewall also referred to as Stateful packet inspection is a network-based firewall that individually tracks sessions of network connections traversing it, and it operates by monitoring active connections making decisions based on the state of the traffic. Next-Generation Firewall (NGFW) is a part of the third generation of firewall technology, combining a conventional firewall with other network device filtering functions, such as an application firewall using in-line Deep Packet Inspection (DPI), an intrusion prevention system (IPS). Firewall weakness in several types of networks caused negative effects and drop down the network and broke over the privacy. We create a scenario based on TCP protocol to evaluate the efficiency of the firewall based on two main measurement elements that represent accuracy and throughput. Also, this paper provides a comparative analysis of Stateful inspection firewalls and Next Generation Firewalls (NGFWs) within Wide Area Network (WAN) Local Area Network (LAN) environments. In our work, we depend on the eclipse-java-2023 program and use Java language. The results in LAN show that NGFW is much better than the Stateful inspection firewall which gains an accuracy of 68% and throughput of 0.89 packets/ms, While in WAN NGFW is better than the Stateful inspection firewall when using accuracy reaches 56% as performance but when using throughput Stateful inspection firewall better than NGFW reach 1.57 packets/ms.

Downloads

Published

2026-08-26