home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



  F E A T U R E

The 10 Most Important Products of the Decade

Number 9: Check Point FireWall-1

October 2, 2000
By Mike Fratto




Products

Go to No. 8

Check Point Software Technologies' FireWall-1 wasn't the first firewall on the market, but the vendor was certainly driving the market with partnership after partnership and innovation after innovation.

In the early '90s, companies were relying on packet-filter routers to block traffic at the perimeter. A few forward-thinking enterprises were playing with free tools, such as Trusted Information Systems' Firewall Tool Kit (FWTK), in '93 and '94, but few companies were actually going online with a real firewall, and the cracking scene was still very much underground. The need for firewalls was just beginning to develop.

FWTK created the firewall arena by offering proxy-based security. Not only was the proxy transparent to the user and the server, but the real advantage was that the user never connected to the server. Check Point took a different approach: It designed FireWall-1 so the product's stateful inspection keeps track of TCP and UDP connections throughout their duration. If a packet belongs to an existing connection, it's allowed to pass; otherwise, FireWall-1 checks to see if it will be allowed to pass, and then tracks the connection from beginning to end. Stateful inspection is faster than proxy-based but offers less security, because clients make direct connections to servers.

Check Point made FireWall-1, introduced in 1993, the firewall to beat. Although debates raged in the security community over which type of firewall--proxy- or stateful-inspection-based--was more effective, Check Point sidestepped the issue by adding an HTTP proxy to FireWall-1 in version 2.1, released in 1996. The choice was then up to the implementer. FireWall-1 led the market throughout the 1990s, providing access control at the perimeter of private networks. Check Point extended FireWall-1 to the desktop with SecureRemote in 1996, and it continued to add proxies, incorporating SMTP, FTP, rsh, telnet and rlogin in version 4.0.

Where FireWall-1 shines most brightly is in its breadth of integration with third-party software. Rather than building or buying content, e-mail and virus-scanning/filtering systems, Check Point developed OPSEC (Open Platform for Security), which integrated such systems with FireWall-1 enforcement modules. OPSEC's list of integrators has become a "who's who" of network security and includes such notables as Internet Security Systems, Netegrity, RSA Security, Trend Micro and WebTrends Corp.

Of course, work on Check Point's inspection module also continued unabated. New, dynamic protocols have been supported, starting with RealAudio in 1995. Six more protocols were added the following year, as were new platforms for FireWall-1's inspection module, such as Bay Networks' router gear. By the end of 1997, TimeStep's Permit and 3Com's NetBuilder platforms had joined the list of supported systems. Although these additions were aimed at answering analysts' cries for appliance-based firewalls, the actual implementations were limited, and most eventually slipped into the shadows.

Today, the FireWall-1 appliance need is filled by Nokia Corp., which implements FireWall-1 on its routing platform. Nokia's preinstallation of Check Point's firewall software eases start-up costs and reduces downtime for customers seeking a turnkey solution.

Check Point now faces wide-ranging competition. Management-software vendors with comprehensive product lines, such as Computer Associates and Network Associates, are taking aim at Check Point's integration strategy, while the firewall-appliance market is overrun with devices from the likes of NetScreen Technologies, SonicWall and WatchGuard Technologies. Check Point's partner strategy is still the major attraction for a sizable portion of the deployed market, so much so that detractors have attempted to shoot holes in it. The criticism usually centers on a programming library that isn't particularly easy to use and a certification program whose policies are overly strict. For a firewall, though, would you really want it any other way?








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service