home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers




Industry briefs

By Kelly Jackson Higgins
The Firewall Behind The Firewall
The next battleground for firewall vendors: control of the traffic-policy server, which aims to manage the end-to-end security and flow of traffic across a network. This is something many organizations so far have only dreamed about.

Nevertheless, with so-called personal firewalls finding their way onto desktop operating systems like SunSoft's Solaris, multiple levels of firewalls in the network need to know specifically who can access what. This task is beyond the reach of traditional packet-filtering firewall technology--and as a result, perimeter routers are more apt to become part of the enterprise today than serve as a security guard for today's distributed computing enterprise networks.

And that's OK, says Kurt Kruger, the firewall product l ine manager for Cisco Systems. Why spin cycles at the perimeter firewall, Kruger points out, when desktop machines or servers that are inside the walls of the company can do the work more cost effectively and efficiently?

VPNs Fuel Trend Part of what's pushing this trend is the rise of VPNs (virtual private networks), which are springing up everywhere now that firewalls and other VPN products have adopted early versions of the IETF's long-awaited and long-delayed IPSec (IP Security) protocol for encrypting IP communication links.

The stage is set for managing the flow of IP traffic both into and out of the enterprise network with a next-generation policy server that sees all and knows all when it comes to firewalling, encrypting, authenticating and managing network bandwidth.

Key players include Cisco, which is working with Microsoft Corp. under the Cisco Enterprise Security Alliance, as well as Sun Microsystems, parent of SunSoft, whose new SunScreen software folds firewalling into Solaris.

Cisco's Kruger says the company's development work on Microsoft's Active Directory in Windows NT will yield an important piece of the centralized policy infrastructure. Part of the challenge is that users usually don't stay in one place--they dial into the corporate network from their notebook computers or log on from another office within the company, and a security policy needs to adjust to this type of usage. That's where a centralized policy infrastructure would come into play, according to Kruger.

Filtering Layers Content filtering already is getting more sophisticated. You no longer have to completely block or welcome all Java applets for security reasons, for instance. Sun's SunScreen firewall software lets in only those Java applets that are digitally signed by trusted entities or vendors. That's a more sophisticated and efficient way to filter Java applets than through ordinary "on-off" switches or methods like scanning the entire applet from top to bottom.

Next enter the traffic-policy server. This centralized policy server--or, more likely, servers--would ensure that all secured nodes and devices are run by a unified security policy within an organization. Without a consistent security policy, your network isn't necessarily secure, Kruger says.

The emerging trend is for vendors to place some measure of security in every network component, says Chris Tolles, director of product marketing at Sun, in much the same way that firewalls eventually will be linked to LDAP directories and network management systems. Later this year Sun will integrate its SunScreen firewall into its directory and tie SunScreen into its Solstice network management system, according to the company.

Early versions of the new breed of traffic-policy server--such as Check Point Software's FireWall-1 management console--manage router access control lists, virus scanning tools, authentication, encryption, network address translation and some content security. But the idea is for these servers to oversee the traffic policy of an entire distributed network, according to Jacqueline Ross, vice president of marketing at Check Point Software. She says it all goes back to the security manager's Holy Grail: to have a single security and traffic policy that encompasses the entire enterprise network.


In-Depth News Analysis
S/MIME And OpenPGP Vie For Security Title
by Kelly Jackson Higgins






Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights