A mechanism that monitors traffic and blocks anything not permitted.
There are several types -- packet filtering, stateful inspection, next-generation firewall (NGFW) -- differing in which layer they can inspect and their performance characteristics. Depending on how the ACLs are designed, "over-blocking" legitimate traffic is also one of the common issues encountered in practice.
© 2026 ITBGM