Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

4/22/2016
09:30 AM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
100%
0%

5 Features to Look For In A Next-Generation Firewall

When it comes to NGFWs, it's the integration that counts.
Previous
1 of 6
Next

Sure, the term next-generation firewall (NGFW) has been around since 2007 and the vendors have been hyping these products for a close to a decade.

So what’s new this year?

Adam Hils, research director, network security, at Gartner, says what’s different about today’s NGFWs is the integration of features such as an IPS or URL filtering within the firewall itself.

“Many SMBs go with UTMs and they have all the features companies need, but there’s really not much integration,” he says. “For the enterprise, companies should think about a next-generation firewall and evaluate how well they integrate multiple features right within the firewall.”

Gartner estimates that the global firewall market will grow from $8.3 billion in 2015 to $9.7 billion in 2017. Hils says these products need to support complex environments, including branch offices, demilitarized zones and virtual environments within the data center. Many of these products also offer centralized management and reporting consoles and claim to do analytics, but companies should look for integration with products like Splunk if they are really serious about doing analytics.

Vendors Gartner gives high marks to include Check Point Software Technologies and Palo Alto Networks, which are assigned leader status, as well as Cisco Systems and Fortinet. Other more niche players include Juniper Networks, Dell SonicWall, Intel Security, Huawei, WatchGuard and Barracuda Networks.

While there are many vendors to choose from, the following slideshow outlines the five main features IT that security managers should consider before selecting a product.

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio
 

Recommended Reading:

Previous
1 of 6
Next
Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
4/24/2016 | 10:53:25 AM
Performance, et al.
In terms of performance, I think it's also important to look at how NGFWs perform in "regular" tests and how they perform in real-world or simulated real-world environments for the purposes for which they'll be used.  Testing by companies such as NSS Labs has shown substantial differences here.

And, of course, don't forget total cost of ownership!  ;)
hewenthatway
50%
50%
hewenthatway,
User Rank: Strategist
4/26/2016 | 4:22:22 AM
gotta love stateful walls.
i love my big ngfw's...have did all the training on dell and fortinet and cisco with the certs and cant move on without becoming a "partner" of dell or pay sans crazy $ to proceed :(

sonicwalls integration with rsyslogs and some of the new logging and analytics (splunk) and machine data aggregation is cool too.  What worries me is the fact that you are in essence sending your most crucial logs and means of tracking down an attacker to another network (cloud) and having faith that the data wont be mined and activities tracked by a 3rd party.

It seems as if this would be a prime target with a large attack surface for a big brother type to harvest and there are a lot poping up nowadays.

Or perhaps all you can do is have your logs done in house or at best smtp smnp or ftps behind said firewall and block all the ports and protocols that you can and auth as much as u can ;) 

the ssl/tls dpi, vpn, ids, ips, application filtering, l2 bridging are bonus's imho

#EDIT  the log system i was thinking of was "smnp (v3)", "not as earlier smtp"
hewenthatway
50%
50%
hewenthatway,
User Rank: Strategist
4/26/2016 | 4:45:45 AM
Re: gotta love stateful walls.
Reply to Joe...

The throroughput on some of these puts you off when u first realize it.


Every ips, ids, deep packet inspection feature costs you crazy thoroughput/

On a 350mb/s connection i only get 175mb/s
Dr.T
100%
0%
Dr.T,
User Rank: Ninja
4/27/2016 | 12:42:58 PM
Firewall vs. Security
I enjoyed reading the article. Firewall and security are not the same think anymore. It is good that IPS is part of modern firewalls but  that is not what is helping in reality today. There is no intrusion but there is an attack.  We just heard a ransomware  attack today where they had bot IDS and IPS enabled in their network.

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/27/2016 | 12:45:43 PM
Re: Performance, et al.
 "... I think it's also important to look at how NGFWs perform ..."

I agree. The performance of doing its job with a high speed so it is not a bottleneck in the network but also with a high quality so it does not make false positive decisions.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/27/2016 | 12:49:37 PM
Re: gotta love stateful walls.
"...you can do is have your logs done in house ..."

Good point. If this is your perimeter firewall everything coming to your network in passing over it so it has real sensitive information where your log is actually your data. I could not give it to a third party.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/27/2016 | 12:53:09 PM
Re: gotta love stateful walls.
"... Every ips, ids, deep packet inspection feature costs you crazy throughput"

Not only that but also the false positives of IPS. Ceratin packets would be dropped and that would increase traffic in the network so waste of effort.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/27/2016 | 12:58:53 PM
Firewalls and cost
 

Another point I would like to make is that the more complex the firewalls get the more expensive they will be for sure.  The problem is that does not solve our security issues, we need a layered approach when it comes to implementing security measures in our infrastructures to avoid vulnerabilities being exploited. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/5/2016 | 7:27:36 AM
Re: gotta love stateful walls.
@hewent: You're not the only one with such concerns.  Indeed, the US cloud industry has lost dozens of billions of dollars since the Snowden revelations because of people being concerned about federal spooks spying on their cloud-stored data (or, for that matter, hackers using the same backdoors the feds were).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
5/7/2016 | 8:03:44 AM
Re: Firewalls and cost
@Dr.T: It's worth pointing out that if you consider total cost of ownership (TCO) as opposed to initial purchase price, the most secure or most cost-effective NGFW is not necessarily going to be the most expensive.

NSS Labs just did an interesting study on this; I reported about it for Dark Reading's sister site, Network Computing, here: networkcomputing.com/network-security/next-generation-firewalls-put-test/379303122

(That said, however, the Palo Alto NGFW tested in this reportedly has a huge initial purchase price and TCO, but performed extremely well in almost all security and performance tests.  It didn't make the "Recommended" cut for NSS Labs strictly because of cost issues.)
Page 1 / 2   >   >>
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25514
PUBLISHED: 2020-09-22
Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.
CVE-2020-25515
PUBLISHED: 2020-09-22
Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books.
CVE-2020-14022
PUBLISHED: 2020-09-22
Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the "Application Star...
CVE-2020-14023
PUBLISHED: 2020-09-22
Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS.
CVE-2020-14024
PUBLISHED: 2020-09-22
Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field in the Group configuration of addresses, (3) listname field in the Defining address lists configuratio...