Upcoming Events

A Network Computing Webinar:
Avoiding Downtime: How Virtualization Can Help In Times of Trouble

June 12, 2013
11:00 AM PT / 2:00 PM ET

Are you caught between a desire for the benefits of the cloud and concerns about security and control? Then you should attend this insight-packed webinar to learn how private data networking technologies like MPLS IP-VPNs can address your concerns and allow you to safely and intelligently reap the savings, agility and other benefits associated with cloud computing.

Join us to hear top industry experts discuss the private data network technologies that are best suited for enterprise cloud access requirements. You won't want to miss this opportunity to learn how your organization can best mitigate risk while reaping the full potential benefits of the cloud.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Skybox Brings Firewall Management To The Masses

For busy IT and security administrators, firewalls are akin to the home attic--a lot of stuff accumulates in there over time, and you'd feel better if you cleaned it out, but who's got time? New software from Skybox Security aims to help mid-size shops stop making excuses. The software, called Skybox CertiFire, collects and analyzes firewall configurations to help ensure firewall rules match corporate security policies, spot critical gaps that could lead to trouble and eliminate redundant rules.

"Five years after you set up a firewall, it's got hundreds of rules, and no one knows why some of those rules where put there," says Gidi Cohen, CEO of Skybox Security. CertiFire is built for mid-market organizations, which Skybox describes as companies with one hundred or more employees and more than one firewall in place. The product works out of the box with firewalls from Check Point, Cisco Systems, Juniper Networks and Fortinet. The company says more firewalls are on the roadmap. CertiFire can connect directly to a firewall to ingest its rule set, or administrators can upload configuration files into CertiFire.

Once the configurations are loaded, the software analyzes them. The software compares actual rule sets against corporate policies to look for discrepancies. It will also highlight redundant rules or rules that conflict with one another. It also includes out-of-the-box compliance checks for programs such as PCI. The software can also help ensure that ongoing changes made to firewalls don't expose the organization to unintended risks that will adversely affect regular network service. Administrators can generate reports for internal use and to provide to auditors.

Unlike some competing firewall management products, including Skybox's own enterprise version, Firewall Compliance Auditor, CertiFire does not analyze configurations for other network devices such as switches or routers. It also doesn't integrate with help-desk ticketing systems. This might be a problem in larger organizations that have separate security and network groups, where change requests must follow a standard workflow, but given CertiFire's mid-market target audience, this probably won't be a deal-breaker for many shops.

CertiFire is available immediately. Pricing starts at $630 per firewall per/year for ten CertiFire licenses. The company also offers a 14-day free download for up to five firewalls to let potential customers try the software.


Related Reading


More Insights


Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 
Vendor Comparisons
Network Computing’s Vendor Comparisons provide extensive details on products and services, including downloadable feature matrices. Our categories include:

Research and Reports

May 2013
Network Computing: May 2013


TechWeb Careers