home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security
F E A T U R E  
Defense Mechanisms

  November 12, 2001
  By Mike Fratto


There's no question that firewalls are a key weapon in the IT arsenal. From a business perspective, the case for purchasing the right firewall for the job at hand is simple: Downtime costs money. Lost data costs money. A hacked site that makes your company look idiotic can cost you mind share and brand credibility. But just as the amount of barbed wire or the number of dead bolts you install depends on the area to be protected, you have to pick the right firewall for the task.



We've seen it again and again: As technology product categories mature, they become more specialized. Firewalls are no different. They are applications that must be deployed and must be managed, monitored and maintained, just like any other application.

Why an application? Because one firewall does not fit all needs. A wide range of desktop firewalls is available, hosting providers can purchase collocated or SOHO firewalls, and enterprises can provide significant improvement in reliability with high-availability firewalls. A hosted environment needs firewalls that can be managed separately and provide high-availability features. SOHO (small office/home office) firewalls that an MSP (managed service provider) would deploy require strong multiunit/multicustomer management. The same technology, in some cases the same products, should be selected and deployed based on specific needs.

What Do Readers Think?

Check out our e-poll results on personal firewalls.

We have identified four major firewall application areas: the high-availability firewall guarding the network perimeter, collocated firewalls aimed at the xSP multitenant market, SOHO firewalls that an MSP would deploy and administer, and centrally managed desktop firewalls aimed at the corporate desktop. And each has its own requirements.

Our Testing

While each review in this package focuses on specific features and deployments, we did see some trends. From a security standpoint, the firewalls we tested provided the functionality they claimed, passing and blocking traffic according to our security policy. Management and reporting play a key role in a successful large-scale rollout: Administering 1,000-plus firewalls requires strong bulk configuration and tiered management capabilities. In all cases, we found event logging to be a mixed bag, ranging from useful to pathetic.

We all have experienced catastrophic firewall failures. The debate over ASIC-based appliances versus the general-purpose hardware-OS firewall goes beyond mere performance. ASIC-based firewalls recover faster and more reliably than the general-purpose firewalls. That in itself is a compelling argument. In addition, if the problem is software, then a fast recovery method is integral to keeping your data flowing. The last thing you want to do is spend hours installing and configuring a general-purpose OS, then setting up the firewall on top of that. This further strengthens the case for ASIC-based firewalls.

Of course, as Gigabit Ethernet picks up steam, firewalls are being used to support much higher bandwidth networks. This is a leap in magnitude of performance over Fast Ethernet, and even vendors' own published numbers are below the top end of 2 Gbps. More important, it's not the amount of data traveling through the firewall that causes performance degradation; there is strong evidence that state-table management is still a huge problem, as we saw firewalls collapse under the weight of a Class Bęworth of client IP addresses (65,535 distinct addresses).

Each firewall has its strengths and weaknesses and was scored accordingly. In fact, no single vendor's products swept the reviews, which confirms what we suspected all along: The requirements of the application should drive the technology purchasing decision, not the other way around.


   Page: 1 | 2 | 3 | 4 | 5 | Next Page





Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service