The answer to question 01: Protocol type, IP destination, and source, port number. The answer to question 02: OSI layer 7. The reason is that the NGFW is configured with application-specific filters that can parse the contents of protocols such as HTTP, SMTP, etc. The answer to question 03: Blocking access based on time of day or total usage. The answer to question 04: