Sei sulla pagina 1di 7

BUYERS GUIDE

What to Look for


in Next-Generation
Firewalls
An NGFW is a major technology purchase.
Understanding product features and capabilities,
and having a clear sense of your real security
requirements, is critical to choosing the
best product.
BY MIGUEL O. VILLEGAS
BUYERS GUIDE

What to Look for


in Next-Generation
Firewalls
What to Look for in Next-Generation Firewalls

Choosing the best next- NGFWs EXPLAINED HOW AN NGFW WORKS


generation firewall for your Next-generation firewalls are The best next-generation fire-
particular enterprise requires a integrated, hardware- or soft- wall is one that is comprehen-
thorough understanding of the ware-based, network security sive, flexible and easy to use.
varieties of NGFW technology platforms. They were developed To be comprehensive, an
available so that product-to- as a means to detect and block NGFW should include intru-
product comparisons can be sophisticated attacks beyond the sion prevention, antivirus/mal-
correctly and efficiently made. abilities of traditional firewall ware prevention, application
NGFWs are available in a vari- technologies. control, deep packet inspection
ety of configurations and price The next-gen firewalls avail- (DPI) andstateful inspection,
ranges. able on the market today can encryption, compression, qual-
This Buyers Guide explains vary significantly from one ity of service (QoS) and other
the essence of next-gen firewall another in many ways, includ- capabilities.
technology and which features ing both price and the specific Second, NFGWs must be flex-
provide what type of protection features provided. Choosing the ible, which also means scalable,
for company networks. best next-generation firewall so that features can be modu-
requires careful study of the larized and activated based on
STAY CONNECTED! technology in general, and an need.
Follow @SearchSecurity today. understanding of your systems Finally, NFGWs must be easy
particular needs. to use, with a fairly intuitive

2 EXPLAINED HOW IT WORKS FEATURES THE BOTTOM LINE


BUYERS GUIDE
management interface that pro- FEATURES TO LOOK FOR firewalls are hardware, software,
What to Look for
in Next-Generation vides a clean and easy-to-read Most NFGWs are appliance- or cloud-based. Hardware-based
Firewalls
dashboard, feature activations, based, but some are available as NGFWs appeal to large and mid-
rule-set definitions, configu- virtual products (software) so size enterprises; software-based
ration analysis, vulnerability that enterprises can install them NGFWs suit small companies
assessments, activity reports on their own servers. Some with simple network infrastruc-
and alerts. NGFWs are delivered over the tures; and cloud-based NGFWs
Some NGFW features are cloud as asoftware as a service. to highly decentralized, multilo-
more robust and advanced than Most are modular, such that an cation sites or enterprises where
others. So it is incumbent upon enterprise can choose to pur- the required skill set to manage
customers to carefully vet the chase and activate features com- them is wanting or reallocated.
features of individual products mensurate with their specific
to determine the best next- needs and risks. Feature set: Not all vendors
generation firewall for them. For It is important that organiza- offer all NGFW features. Typi-
example, not all NGFWs pro- tions familiarize themselves cal NGFW features include
videtwo-factor authenticationor with the vendors and products inline DPI, IDS/IPS, application
mobile device security. But then that best fit their IT environ- inspection and control,SSL/
again, not every customer needs ments and business models. SSHinspection,website filter-
those features. And while there There are six criteria to con- ingand QoS/bandwidth man-
are those NGFW vendors that sider: platform base, feature set, agement to protect networks
say their product supports such performance, manageability, against the latest in sophis-
features, some of these might price and support. ticated network attacks and
require additional modules or intrusion.
products in order to make them Platform type: How is the NFGW Other common NGFW fea-
work. product provided? Next-gen tures include DLP, threat

3 EXPLAINED HOW IT WORKS FEATURES THE BOTTOM LINE


BUYERS GUIDE
intelligence,mobile device secu- the organization is buying and Manageability: Manageability
What to Look for
in Next-Generation rity,data loss prevention(DLP), whether or not it provides the refers to system configuration
Firewalls
Active Directory integration and level of protection required for requirements and usability of
an open architecture that allows each specific area of desired the management console. The
clients to tailor application con- security. 2015 GartnerMagic Quadrantfor
trol and even some firewall rule Enterprise Network Firewalls
definitions. Performance: Because they inte- evaluation criteria includes
An important caveat is that grate many features into a single operations and manageability as
the bevy of features available in appliance, a next-generation important factors. It considers
NGFWsoutside of traditional firewall may seem attractive to how the NGFW manages com-
firewall blocking and tackling some organizations. However, plex environments with many
are not full complements. In enabling all available features at firewalls and users and very nar-
other words, an NGFWs DLP is once could result in serious per- row firewall change windows.
not at the level of the full-fea- formance degradation. System configuration changes
ture DLP typically provided by It is true that NGFW perfor- and the user interface of the
a dedicated DLP product. Simi- mance metrics have improved management console should be
larly, NGFW application con- over the years. But nevertheless, comprehensive, flexible and easy
trol provides identification and the buyer still needs to seri- to use.
authorization of defined applica- ously consider performance in Specifically, the best NGFW
tions, user access and additional relationship to the security fea- would (1) be comprehensive,
time-of-day and upload/down- tures they want to enable when such that it covers an array of
load permissions, but does not determining which vendors to features that preclude the need
provide deep packet or content approach and what model is the for augmentation by other point
filtering of the application. best next-generation firewall for solutions; (2) allow the exclusion
The key is to know what their company. of features that are not needed

4 EXPLAINED HOW IT WORKS FEATURES THE BOTTOM LINE


BUYERS GUIDE
in the enterprise environment; If possible, do not immediately choosing the best NGFW for
What to Look for
in Next-Generation and (3) be easy to use, such agree to the retail price named. your company. Obtain refer-
Firewalls
that the management console, Most vendors will provide vol- ences and ask to speak with ven-
individual feature dashboards ume discounts (the more users dor clients without the vendor
and reporting are intuitive and supported the less it costs per present.
incisive. user, for example) or discounts Support criteria for NGFWs
with viable prospects of further should address responsive-
Price: NGFW appliance, soft- purchases. ness ranked by type of service
ware and cloud service pricing Overall, pricing should be one request, quality and accuracy of
varies considerably by vendor of several factors in determining the service response, currency of
and model, with prices ranging the total cost of ownership. For product updates, and customer
from several hundred dollars to example, the TCO of a NGFW education and awareness of cur-
many tens of thousands of dol- is not just the purchase price, rent events.
lars. Some are even priced by but also the expenses incurred
the number of users (e.g., $1,100 through its use, maintenance,
for 1-99 users to $100,000 for support and operation. A NGFW THE BOTTOM LINE
5,000 users+). All, meanwhile, that appears to be a great bargain Next-generation firewalls offer
have separate pricing for service might actually have a TCO that a good complement of security
contracts. is higher than that of another point products that, although
Closely review individual NGFW, or even a combination of not yet the silver bullet, address
product offerings to determine point solutions. many network security con-
what features are best for your cerns. NGFWs are not for every-
enterprise, factoring in what Support: Given the critical nature one, however. When deciding
the organization can afford and of NGFWs, timely and accu- whether or not to deploy the
what it cannot afford to have. rate support is essential when technology (or when making a

5 EXPLAINED HOW IT WORKS FEATURES THE BOTTOM LINE


BUYERS GUIDE
business case to management), Migrating to a NGFW often provided in a box.
What to Look for
in Next-Generation first determine if the investment requires a considerable expendi- While savings over the long
Firewalls
in an integrated NGFW security ture and architectural remedia- haul could be considerable
product is justifiable, is aligned tion effort in the short run. For with a NGFW, and the efficacy
with existing IT strategies and some organizations, that may of integrated security is well
has a well-defined TCO. exceed the benefits of convert- known, the decision to take the
In order to determine the best ing, especially if their initial plunge now or wait until later
next-generation firewall for investment for their existing comes down to the level of com-
their enterprises, potential pur- point products deployment has mitment and resources available
chasers also need to look at their been significant. to an organization. n
network architecture, threat Nonetheless, converting to a
vectors and risk appetite to NGFW realizes substantial sav- MIGUEL O. MIKE VILLEGAS is vice presi-
determine if point products or ings (not just in money, but in dent for K3DES LLC, a payment and tech-
NGFWs are the best approach. time and effort in support and nology consulting firm. Over a span of 30
years, Villegas has been a CISO for a large
That said, NGFWs do provide a management) over time. And
online retailer, partner for two Big Four
single vendor, architecture and because they are integrated, an consulting firms over a span of nine years,
management interface for more NGFW tends to be more effec- vice president of IT risk management, an IT
flexibility in providing differing tive because of the combination audit director for several large commercial
levels of protection, common of security services it provides banks, and owner of an information security
professionals firm. He is past president of
reporting and, typically, a cost that have been designed, tested
the Los Angeles and San Francisco ISACA
reduction by negating the need and vetted to work together. chapters and holds many certifications, in-
to purchase separate security Much of the integration, that cluding CISA, CISSP, GSEC, CEH, QSA and
appliances and services. is, has already been done and PA-QSA.

6 EXPLAINED HOW IT WORKS FEATURES THE BOTTOM LINE


This Buyers Guide, What to Look for in Next-Generation Firewalls, is a SearchSecurity e-publication.

Robert Richardson | Editorial Director

Kara Gattine | Executive Managing Editor

Brenda L. Horrigan | Managing Editor

Robert Wright | Site Editor

Peter Loshin | Site Editor

Linda Koury | Director of Online Design

Jacquelyn Howard | Senior Director, Editorial Production

Joe Hebert | Managing Editor, E-Products

Doug Olender | Senior Vice President/Group Publisher | dolender@techtarget.com

TechTarget 275 Grove Street, Newton, MA 02466


www.techtarget.com

2016 TechTarget Inc. No part of this publication may be transmitted or reproduced in any form or by any means without written
permission from the publisher. TechTarget reprints are available through The YGS Group.
About TechTarget: TechTarget publishes media for information technology professionals. More than 100 focused websites enable quick access to a deep store
of news, advice and analysis about the technologies, products and processes crucial to your job. Our live and virtual events give you direct access to independent
expert commentary and advice. At IT Knowledge Exchange, our social community, you can get advice and share solutions with peers and experts.

Potrebbero piacerti anche