Chapter 10 Install and System Administration for FortiOS 5.0 : FortiGuard : FortiGuard Services : Next Generation Firewall
  
Next Generation Firewall
The Next Generation Firewall (NGFW) offers integrated, high-performance protection against today's wide range of advanced threats targeting your applications, data, and users.
NGFW services include:
Intrusion Prevention System (IPS)- The FortiGuard Intrusion Prevention System (IPS) uses a customizable database of more than 4000 known threats to stop attacks that evade conventional firewall defenses. It also provides behavior-based heuristics, enabling the system to recognize threats when no signature has yet been developed. It also provides more than 1000 application identity signatures for complete application control.
Application Control - Application Control allows you to identify and control applications on networks and endpoints regardless of port, protocol, and IP address used. It gives you unmatched visibility and control over application traffic, even traffic from unknown applications and sources.