A stateful firewall remembers the connections it has allowed and judges every packet against that record. A stateless firewall judges each packet alone, against a static list of rules, with no memory of what came before.
That difference decides how many rules you write, which forged packets get through, and what breaks under load. Nearly every firewall a business buys today is stateful. Stateless filtering survives in router access control lists, in cloud network ACLs, and in front of firewalls that need protecting.
- Stateful firewalls track connections. Stateless firewalls inspect individual packets in isolation
- A stateful rule allows a conversation. A stateless rule allows one direction of it
- You almost never choose between them when buying, because the firewall is stateful
- Stateless rules still matter on routers and in cloud network ACLs
- State has a cost: asymmetric routing and a full state table both break a stateful firewall
On this page
StatelessHow a stateless firewall decides
A stateless firewall is a packet filter. It holds an ordered list of predefined rules and compares every data packet with that list, based on header information: source and destination IP address, protocol, source and destination port, and sometimes the TCP flags. The first rule that matches decides, allow or deny.
Nothing is remembered. Stateless firewalls have no context: the filter does not know whether a packet starts a connection, continues one, or belongs to no connection at all. Two packets from the same session are strangers to it.
Every administrator meets the consequence on day one. Network traffic runs in two directions, and a stateless filter needs a rule for each. Letting staff browse the web means one rule for outgoing traffic to port 443, and a second rule allowing replies from port 443 to a wide range of high numbered client ports.
The second rule is the weak point. It cannot tell a genuine reply from a forged packet that claims to come from port 443. The patch is to match TCP flags, such as the established keyword on a Cisco access list, which admits only segments with ACK or RST set. Attackers can set it too.
What stateless filtering gives in return is speed and predictability. Matching header fields against static rules is cheap, runs in hardware on routers and switches, uses no memory per connection, and behaves the same under any traffic load.
StatefulHow a stateful firewall decides
A stateful firewall starts with the same rule list and adds memory. When a packet opens a new connection and a rule allows it, the firewall writes an entry in its state table: both IP addresses, both ports, the protocol, and where the connection stands. Every later packet is checked against the state table first.
For TCP the firewall follows the three way handshake. It expects a SYN, then a SYN and ACK coming back, then an ACK, and it tracks sequence numbers and the closing FIN or RST. A packet that claims to be part of an established connection that does not exist is dropped, whatever its flags say.
UDP and ICMP have no handshake, so the firewall builds a pseudo state. An outgoing DNS query creates a short lived entry, and a reply matching the same addresses and ports is accepted until a timer expires. It is weaker than TCP tracking, and far better than a permanent rule admitting anything from port 53.
This is what vendors call stateful inspection or stateful packet inspection, and it changes how security rules are written. One rule says staff may open connections to the web. Return traffic is allowed because it matches existing connections, not because a rule invites it. Fewer rules, and none is a standing hole for inbound traffic.
State tracking also handles protocols that open a second connection on a negotiated port. Active mode FTP and some voice protocols do this. A stateful firewall with a helper for the protocol reads the negotiation and expects the related connection. A stateless filter can only leave the whole port range open.
BuyingNearly every firewall you can buy is stateful
Most articles on stateful vs stateless firewall end by asking you to weigh two types of firewalls and choose. For a business buying network security, that choice is gone. Current business firewalls, from a small office appliance to a data center cluster, do stateful inspection. So do host firewalls in desktop and server operating systems.
Next generation firewalls are stateful firewalls with more layers on top: application awareness, intrusion prevention against known threats, TLS inspection, user identity. Connection tracking is the floor those features stand on. The comparison that matters is between those upper layers, which the pages on what a firewall is and IDS vs IPS cover.
So treat the stateful vs stateless firewall question as a question about where you are writing rules, not about which box to buy. On the firewall, you write stateful rules. In several other places on the same network, you write stateless ones, often without the interface saying so.
Still statelessWhere stateless filtering still lives
Router and switch ACLs. An access control list on a router or layer 3 switch is stateless. It is the tool for filtering between VLANs at wire speed, locking down management access, and dropping obviously bad traffic at the internet edge before it reaches the firewall. Remember the return path every time you write one.
Cloud network ACLs. AWS documents the split plainly: security groups are stateful, so responses to allowed traffic flow regardless of the rules in the other direction, while network ACLs are stateless and return traffic must be explicitly allowed. AWS recommends security groups as the primary control. Azure network security groups are stateful.
In front of the firewall during an attack. A flood of packets that never complete a connection fills a state table. A stateless filter upstream can drop that traffic without storing anything about it, which is why DDoS scrubbing and provider edge filtering lean on stateless rules.
Very high throughput paths. Where traffic is simple, trusted and enormous, such as storage or backbone links, static rules in hardware protect without adding a state lookup to every packet.
Failure modesWhat goes wrong with state
State is what makes a stateful firewall secure, and it is also the thing that fails. Two failures account for most of the confusing outages.
Asymmetric routing. A stateful firewall must see both directions of a connection. If outbound packets leave through one firewall and the replies return through another, the second has no state table entry and drops them. It appears after adding a second internet link, a second VPN path, or a redundant gateway pair without state synchronization.
The symptoms are distinctive. Ping works, because many firewalls are forgiving with ICMP. TCP connections hang after the SYN, or work from one subnet and not from another. The fix is to make routing symmetric, or to use a firewall cluster that shares its state table between members.
State table exhaustion. Every tracked connection uses memory, and the table has a maximum size. A SYN flood, a scanning worm on an infected PC, or a busy server behind an undersized firewall can fill it. When it is full, new connections are refused while existing ones keep working, which makes the outage look random.
Check the concurrent connection limit on a datasheet as carefully as the throughput figure, watch the connection count in monitoring, and leave timeouts at vendor defaults unless you know why you are changing them.
PitfallsWhere people go wrong
Writing a cloud network ACL as if it were a security group. The inbound rule is there, the application still fails, and nobody thinks about the reply leaving on an ephemeral port. Stateless rules need both directions, every time.
Treating the choice as a purchase decision. Comparing stateful and stateless firewalls on a shortlist wastes time. Both types of firewalls work from the same information in the packet header. Compare inspection features, connection capacity, licensing and management instead.
Opening a wide inbound port range on a router ACL and forgetting it. A rule that admits anything from port 443 to high ports is a standing hole. Where an ACL is the only filter, at least match established TCP traffic, and put a stateful firewall behind it.
Adding a second path without thinking about state. Dual internet links and active to active firewall pairs need symmetric routing or state synchronization. Test failover with real TCP sessions, not with ping.
Sizing a firewall on throughput alone. Many small connections exhaust the state table long before the bandwidth figure is reached. Guest Wi-Fi, DNS servers and web proxies are the usual culprits.
Assuming stateful means it inspects content. Stateful firewalls track connections at the network and transport layers. They do not read the data inside. Application layer attacks and malware inside an allowed HTTPS session pass a purely stateful firewall untouched, because the rules only ever asked who was talking to whom.
ComparisonStateless and stateful filtering, row by row
| Criterion | Stateless firewall | Stateful firewall |
|---|---|---|
| Decides on | Each packet alone, against static rules | The packet plus the state of its connection |
| Return traffic | Needs its own rule | Allowed automatically for existing connections |
| Forged packets claiming to be replies | Often pass | Dropped, no matching connection |
| Rules needed | Two per flow, one each way | One per flow |
| Memory and CPU per connection | None | Some, for every tracked connection |
| Behavior under a connection flood | Unchanged | State table can fill |
| Asymmetric routing | Not a problem | Breaks connections |
| Where you meet it | Router ACLs, cloud network ACLs | Every business firewall, host firewalls, cloud security groups |
The rows on forged packets and rule count are why stateful firewalls won: they are more secure and easier to run. The rows on flooding and asymmetric routing are why stateless filtering never went away. A sound network uses both, the stateful firewall for policy and stateless rules around it for coarse, cheap filtering.
FAQFrequently asked questions
What is the difference between a stateful and a stateless firewall?
A stateful firewall keeps a table of active connections and checks each packet against it, so replies are allowed automatically and forged packets are dropped. A stateless firewall checks every packet on its own against static rules and remembers nothing between packets.
What is a stateful firewall in simple terms?
A firewall with a memory. It notes every connection it allows, then lets through only packets that belong to one of those connections or that a rule permits as a new one. Anything claiming to be part of a conversation it never saw is dropped.
What is a stateless firewall?
A packet filter that compares the header of each packet with a fixed rule list: addresses, ports, protocol and sometimes TCP flags. It is fast and uses no memory per connection, and it cannot tell a genuine reply from a forged one.
Stateless vs stateful firewall: which is more secure?
Stateful. It validates that packets fit a real connection, follows the TCP handshake, and needs no permanent inbound rule for return traffic. Stateless filtering is still useful as a fast outer layer, and it is not enough on its own at an internet edge.
What is stateful inspection?
The technique of tracking each connection through its life, from the opening packet to the close or timeout, and using that record to judge later packets. Stateful packet inspection and dynamic packet filtering are other names for the same thing.
Is stateful packet inspection the same as deep packet inspection?
No. Stateful packet inspection follows connections using header information at layers 3 and 4. Deep packet inspection reads the payload to identify applications and threats. Next generation firewalls do both, with stateful tracking as the base.
Are AWS security groups stateful or stateless?
Stateful. AWS documentation says response traffic for an allowed request is permitted regardless of the rules in the other direction. AWS network ACLs are stateless, so return traffic must be explicitly allowed with its own rule.
Is a packet filtering firewall the same as a stateless firewall?
In everyday use, yes. Packet filtering firewalls make decisions based on header information in each packet, without context from earlier traffic. Stateful firewalls are sometimes called dynamic packet filters, because they add connection tracking on top of the same header checks.
How does a stateful firewall handle UDP?
UDP has no handshake, so the firewall creates a temporary entry when a packet goes out and accepts matching replies until a timer expires. It is a pseudo state, weaker than TCP tracking and much safer than a permanent rule.
What is a state table?
The list of connections a stateful firewall is tracking. Each entry holds the source and destination addresses, ports, protocol, connection state and a timeout. The table has a maximum size, and reaching it stops new connections.
Why does asymmetric routing break a stateful firewall?
The firewall only allows replies that match a connection it saw being opened. If the request left through a different device, there is no entry, so the reply is dropped as invalid. Symmetric routing or state synchronization between firewalls fixes it.
Do I need a stateless firewall if I already have a stateful one?
Not as a separate product. You will still write stateless rules on routers, layer 3 switches and cloud network ACLs, and they are worth having as a coarse first filter that protects the stateful firewall from floods.
Can a router ACL replace a firewall?
No. An ACL filters on header fields with no memory of connections, no protocol awareness and little logging. It is a good supplement at the edge and between VLANs. The policy decision for internet traffic belongs on a stateful firewall.
Keep readingRelated concepts
Read next · Network security What Is a Firewall? How a packet is judged against rules, state and the default deny, and the four things a firewall cannot see. Open this next14 min- Network security · 12 min IDS vs IPS What inspects the traffic a firewall allowed, and why placement decides whether it can block.
- Network security · 9 min The Implicit Deny, and Why the Rule You Just Added Did Nothing Why a permit placed below a broader rule never runs, and how first match ordering decides everything.