Stateful Firewall
L3 and L4 checks decide only from addressing and transport context.
IP header (L3)
Source and destination routing context
Transport (L4)
Port and session state
Payload encrypted
No Layer 7 visibility into the actual application or threat.