¨Has
similar objectives as ASA
¨Dynamically
modifies the extended ACLs to allow return traffic of connections established from
the inside network
¨Inspects transport level and application level
protocols
¨Keeps
track of the number and duration of sessions by inspecting packets
¨