2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
Domain 4 • Chapter 4Section 4.3

4.3 Network Firewalls, Next-Gen DPI & IDS vs. IPS Deployments

Details stateful packet inspection, Layer 7 Next-Generation Firewalls, deep packet inspection, and inline IPS vs. out-of-band IDS deployments.

🎯 Key CompTIA Network+ Exam Takeaways

  • Stateful firewalls maintain a state table to automatically permit return traffic without static inbound rules.
  • Next-Generation Firewalls (NGFWs) perform Layer 7 Deep Packet Inspection (DPI) to identify applications regardless of port.
  • An IPS sits inline to actively block malicious traffic in real time; an IDS sits out-of-band to passively monitor and alert.

Firewalls control traffic between network security zones. Stateless filters inspect individual packets against static ACL rules. Stateful firewalls maintain a state table tracking TCP handshakes and UDP pseudo-connections, dynamically allowing valid return traffic.

Next-Generation Firewalls (NGFWs) operate at Layer 7, utilizing Deep Packet Inspection (DPI) and TLS decryption to classify applications and content regardless of port number, defeating evasive malware that tunnels over HTTPS port 443.

Intrusion prevention systems (IPS) sit directly inline in the packet flow, actively terminating malicious sessions and dropping attacking packets in real time.

⚠️ Common Pearson VUE Exam Traps

  • Relying on port-based Layer 4 firewalls to block modern applications that tunnel over standard ports like HTTPS 443.
  • Confusing an IDS (passive, out-of-band via SPAN, cannot stop packets) with an IPS (active, inline, drops packets).

Knowledge Checkpoint

Knowledge Checkpoint • Section 4.3

An enterprise needs to block employees from accessing unauthorized peer-to-peer (P2P) file sharing and anonymizing proxy applications that circumvent traditional port-based firewall rules by disguising their traffic over TCP port 443. Which security appliance is capable of identifying and blocking this traffic?