The NGFW Package, Layer 7 Made Clear
The base functions from the previous lesson mostly work with addresses, ports and states. The NGFW package goes one level deeper: to Layer 7, the application layer. This lesson explains what that means and what the package actually delivers.
What Layer 7 means compared to Layer 3 and 4
Layer 3 and Layer 4 of the layer model concern addresses and ports: who talks to whom, over which port. A firewall that only works at these layers can see that a machine communicates over port 443, but not necessarily which application is behind it. Layer 7 is the application layer. Here it is about the content and meaning of the communication: is this a video call, a file-sharing service or a social media request. This distinction is the core of what an NGFW package delivers.
The functions at a glance
- Deep packet inspection with application recognition: the package recognizes applications regardless of the port used, even when an application tries to disguise itself.
- Application control with categories: granular control over individual applications or entire categories such as social media or streaming, with separate rules per user group.
- Advanced TLS inspection: deeper analysis of encrypted traffic to detect threats hiding behind encryption.
- Adaptive web filtering across more than 60 categories: web requests are evaluated in real time and allowed or blocked according to defined policies, instead of relying only on static lists.
- Cloud-based threat intelligence system: a continuously updated detection service that incorporates new threats without waiting for manual rule updates.
Licensing and installation
The NGFW package is separately bookable and not part of the base version of AIMdefense. There is a free base tier, but it does not cover the full feature set. The package is installed through the firewall's plugin management.
Limits of TLS inspection
As useful as advanced TLS inspection is, it has limits. Certificate pinning, where an application only accepts one specific certificate, can technically prevent decryption. Breaking open TLS also raises legal questions, for example around employee data protection, which need to be clarified beforehand. And decryption requires processing power, which increases the performance demand on the firewall.
Key point: TLS inspection has limits. Certificate pinning, legal questions and performance requirements always come with it.
Key point: The base version of the NGFW package is free, but it is not the full feature set.
Why this matters for AIMdefense
When someone talks about Layer 7 security in a request, they usually mean exactly these functions. Basic protection is often covered by the standard feature set from lesson 4, the NGFW package adds deeper visibility and control on top.