This document provides a clearer understanding of how NSS Labs evaluates enterprise firewalls in challenging real-world scenarios.

It emphasizes not only the importance of the effectiveness and impact of each capability, but also the potential consequences should something fail. NSS Labs uses a multiplicative model, which weights each category to ensure that critical capabilities are given more impact in the final evaluation. Even minor gaps in coverage can significantly weaken the overall security, as attackers tend to reuse vulnerabilities or evasion techniques once they are discovered.