The document presents a new distributed firewall model based on stateful Cluster Security Gateway (CSG) architecture, addressing limitations of traditional firewalls by enhancing network security through central management and real-time updates. This approach improves tamper resistance, reduces network load, and increases scalability while implementing IPSec for secure policy updates and X.509 certificates for authentication. The architecture consists of components including a network administrator machine, cluster security managers, and a stateful CSG, aiming to provide robust protection against both insider and external attacks.