Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Cisco security exec has big plans for Ironport technology

Upgrades possible for firewalls, VPNs and IPSs
By Tim Greene , Network World , 04/22/2008

Cisco is looking to aggressively incorporate its reputation and monitoring gear into security gear, all under the direction the former CEO of Ironport, the company Cisco bought for its reputation technology.

Scott Weiss, recently promoted to vice president of Cisco's security technology business unit, says reputation could improve the effectiveness of classic security gear starting as soon as year-end.

As head of the security technology unit, Weiss oversees all Cisco firewalls, VPNs, intrusion protection/detection system gear,  Security Manager software, Monitoring, Analysis and Response system (MARS) as well as all the Ironport product line of antispam and Web-filtering products. (Compare firewall, VPN and IPS products.)

"I have a lot of early thoughts about synergies from the Ironport product line, and some of the threat prevention and interrogating of anonymous traffic that we've really built up an expertise with, and how to tie that better in with the firewall and [intrusion-protection system]," Weiss says. "These are things we have hypothesized about before but now we are really putting those product plans into action."

Weiss says he also wants to incorporate a behavioral monitoring feature of Ironport S-Series Web security appliances into Cisco firewalls. The monitoring could alert firewalls to block malicious traffic in and out of the network based on known exploits.

"A lot of silent threats that were not seen could be eliminated on a large-scale basis. That's an early charter we have for the organization," he says. "We've had some meetings of these groups and we've actually put some project plans in place. I think that you could see it as early as eight to 12 months as some of these cross-pollenization efforts."

The monitoring capabilities would help businesses by giving them better data about what traffic is moving across network boundaries. "You have to illuminate what information is leaving the corporation before folks are going to be willing to invest in [security] and some of the Ironport technology will allow us to do that," Weiss says.

He says the capability of Ironport gear to detail traffic in and out of networks and peform threat assessment could help boost the capabilities of IPS products. "IPS as a technology is not that dissimilar from what we do at Ironport, which is interrogating anonymous traffic, things that are coming into the network," Weiss says.

Comments (1)
Login
Forgot your account info?

Cisco security gear + reputation services = good thingBy Cisco Subnet on April 22, 2008, 5:46 pmScott Weiss is right when he says that adding reputation to Cisco's security gear is important. And Cisco is right about giving over control of its classic security...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

Dear Nurse: Putting aside your rudeness I will agree: The Museum of the American Cocktail is, as far...- Mark Gibbs

Join the Discussion