Traditional firewalls and UTMs use port-based policies. If an enterprise purchases an NGFW and uses port-based
policies, these policies are insecure and must be migrated to application-based policies. The migration is a challenge
for NGFW users. First, application traffi must be analyzed before migration, although this cannot guarantee that all
migrated policies are accurate. Second, migrated policies must pass enterprise compliance check. Legacy port-based
policies have been proven and it is impossible to completely abandon them and confiure NGFW policies from scratch.