cisco_trooper wrote: » I would be leaning toward B. A normal firewall performing stateful inspection is not going to address application layer attacks and deep packet inspection isn't going to be able to do it either. A Web application firewall is able to identify known web application attacks that happen at the application layer. The attacks are occurring over legitimate TCP connections and really cannot be addressed by a standard firewall.