Stonesoft's "Advanced Evasion Techniques"
I have been sent some marketing material by a firewall manufacturer called Stonesoft. They make a big deal of blocking what they call "advanced evasion techniques" - they say these are a set of different methods to evade the protection against external attacks provided by a modern firewall. They do not seem to provide many details of the methods - they cite the the need for responsible disclosure - what I have found talks about techniques like sending packets deliberately out of order to confuse the IPS. The provide a free test suite to test whether your existing firewall is vulnerable to these technique. I have not tried this yet, has anyone else?
I am currently looking at new firewalls for my school, and I am not sure whether I should be giving any weight to StoneSoft's claims. There seems some plausibility to what they are saying, but I have found a lack of 3rd party discussion of the issue. Closest I have seen is this stack exchange post from 2010.