I wouldn't say that most users think that blocking ports is the only
thing a firewall should/can do. Almost every device has currently this
basic functionality, including routers, load balancers etc., so
companies buying an expensive firewall expect it to do something more.
The problem is, if they know what, and if they get it or not ;)

actually, the problem is that many companies _don't_ expect the firewall to do anything more. and neither to many admins (unfortunantly including a large percentage of 'security' people)

