IT Brief India - Technology news for CIOs & IT decision-makers
India
SonicWall urges hybrid firewalls for cloud security

SonicWall urges hybrid firewalls for cloud security

Tue, 28th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

SonicWall has outlined the different roles that stateful and stateless firewall inspection play in protecting cloud and virtualised environments, arguing that organisations increasingly benefit from combining both approaches within a single security architecture.

The company said the choice of inspection method affects how network traffic is analysed, influencing security visibility, performance and the ability to detect threats across virtual infrastructure. It added that hybrid deployments have become common as organisations seek to balance protection with throughput.

Traffic inspection

Virtual firewalls inspect network packets before allowing, blocking or logging traffic based on security policies. The inspection method determines whether the firewall operates in a stateful or stateless mode.

According to SonicWall, stateful firewalls maintain information about active network sessions through a dynamic state table. Instead of evaluating packets individually, they assess each packet within the context of an established connection.

The company said this enables the firewall to verify subsequent packets against stored session information, including source and destination addresses, ports and connection status.

Stateful inspection also provides greater visibility into the lifecycle of network connections. SonicWall said this helps identify suspicious activity, detect unauthorised session attempts and validate packets against existing sessions before permitting traffic.

Stateless firewalls operate differently. Each packet is evaluated independently without reference to previous packets or connection history.

The inspection process is based on attributes including source and destination IP addresses, source and destination ports and protocol type. Traffic that matches predefined rules is allowed to pass, while packets that fall outside policy are blocked.

SonicWall said stateless inspection requires less processing overhead because it does not maintain connection information. This allows faster packet handling in environments where throughput and low latency are priorities.

Security roles

The company said the inspection model chosen has implications for the level of security that a virtual firewall can provide.

Stateful inspection is designed to recognise traffic patterns that extend across multiple packets. SonicWall said this makes it more effective at identifying threats such as spoofing attempts and session hijacking that rely on connection context.

The company also said virtualised environments generate increasingly complex east-west traffic between workloads as well as north-south traffic between external networks and applications. Stateful inspection provides additional visibility into these communications by analysing packets within active sessions.

SonicWall said this approach offers better detection of unauthorised sessions, stronger protection against spoofing and session hijacking, enhanced application-layer awareness and greater visibility into workload communications.

Stateless inspection continues to play a role in environments where speed is the primary requirement.

The company said stateless filtering is commonly used for high-speed packet filtering at the network edge, distributed denial-of-service mitigation, access control lists and network routing infrastructure.

Because stateless inspection evaluates packets individually, SonicWall said it cannot detect attacks that span multiple packets or provide awareness of broader session context.

Hybrid approach

SonicWall said many virtual firewall deployments now combine stateful and stateless inspection to improve both performance and security.

Under this model, stateless filtering performs initial packet screening before stateful inspection analyses application-level sessions in greater depth. The company said this layered architecture enables organisations to maintain high throughput while applying more comprehensive security controls where needed.

Selecting the appropriate approach depends on several operational factors, according to SonicWall. These include network traffic volume, security requirements, application sensitivity, infrastructure architecture and performance expectations.

The company said stateful inspection forms the foundation of protection for many cloud and virtualised environments because it provides deeper visibility into network sessions and application behaviour. Stateless filtering complements this by handling high-speed traffic where minimal processing overhead is required.

SonicWall said organisations with mixed workloads are increasingly adopting hybrid firewall architectures that apply stateful and stateless inspection according to the sensitivity and performance requirements of different traffic flows.

The company added that its virtual firewalls are built on a stateful deep packet inspection engine and support security capabilities including intrusion prevention, gateway anti-virus and application control for cloud and virtualised environments.

Learn more: 

Visit SonicWall NSv Series | Advanced Virtual Firewall Solutions
Try it: Start Free Trial