The document discusses different generations of firewalls and intrusion detection and prevention systems (IDPS). It describes the key characteristics of five generations of firewalls from static packet filtering to stateful inspection and kernel proxy firewalls. It also discusses the advantages of network-based IDPS (NIDPS) over host-based IDPS, and describes three common detection methods used by IDPS: signature-based, statistical anomaly-based, and stateful packet inspection. Wireless NIDPS and network behavior analysis systems are also introduced as two subtypes of NIDPS.