Types of firewalls
Packet filter: allow/deny by IP, port, protocol - fast but no session awareness.
Stateful firewall: tracks connections (iptables/nftables, hardware NGFW) - better for TCP/UDP sessions.
Application firewall / WAF: inspects HTTP headers, paths, payloads - Layer 7 policy.