A next-generation firewall, available as a hardware appliance or virtual instance, that combines stateful traffic filtering with deep inspection of the traffic it forwards. Its inspection engine performs intrusion prevention, application identification, URL filtering, and file and malware analysis on flows that pass through it, using threat intelligence updates to recognise known-bad content. Policy, event review, and device configuration are handled from a central management console that administers multiple firewalls.