For this discussion we need to know inside out of these devices.In the main stream security enviornments, proxy firewalls, or application gateway firewalls, are a recent addition. Until a few years ago, the most advanced firewall protection was the stateful inspection firewall was the. Stateful firewalls cannot inspect application layer traffic, while they can monitor open connections. Incase through firewall you are allowing HTTP traffic , then an HTTP based attack cannot be inspected by stateful firewall. Proxy firewalls, on the other hand, combines ability to perform deep application inspections along with stateful inspection technology. They monitor traffic for addtionall sign of attcak and analyze layer 7 protocols, such as HTTP and FTP. The firewall must act as a proxy in order to make this work; that is, with firewall ,the client opens a connection. and the firewall opens a separate connection to the server on the clientís behalf.
Proxy servers, however, donít provide the benefits of a firewall. Like proxy firewalls, they act as a middleman for connections, but they donít provide other fiewall technology or stateful connection. They are generally used to provide performance enhancements (such as caching) and content filtering for local userís Web traffic. Since most proxy firewalls can provide all of the benefits of a proxy server, administrators typically use dedicated proxy servers where they wish to remove the performance load from the firewall.