Skip Links

UTM Firewalls are enterprise ready
In this package: UTM firewalls: Ready for the enterprise | Top trends in enterprise UTM market | How to select enterprise UTM firewalls | Five tips on deploying enterprise UTM

UTM firewalls: Ready for the enterprise

Our testing shows that unified threat management appliances aren't just for the SMB market anymore

By Joel Snyder, Network World
August 30, 2007 04:47 PM ET
  • Print

IT managers at small and midsize businesses like unified threat management appliances - firewalls that layer on antimalware protection, content filtering, antispam and intrusion prevention - because deploying a single, multi-function device reduces costs and simplifies configuration.

However, deciding whether and where to deploy UTM appliances in a large enterprise is a more complicated and difficult decision. The idea of a single point through which all traffic flows as an obvious locus for threat mitigation doesn't work when a network has dozens, hundreds or thousands of distinct locations. Also, because performance is a critical issue in large networks, savvy network managers often seek to distribute threat protection rather than centralize it, simply to reduce the likelihood of a performance bottleneck.

Similarly, the style and quality of threat mitigation features one commonly sees in an SMB UTM may not be of interest to an enterprise, where requirements are more exacting and security architectures are more complex. For example, the antispam features and functionality in UTM firewalls pale compared with those in stand-alone enterprise-class dedicated antispam/antivirus appliances.

Enterprise UTM pros and cons

Pros: Cons:
Complexity: High availability and scalability are dramatically simplified in UTM. Performance: Enabling threat response features causes a huge performance hit and makes performance unpredictable.
Management: A single management interface enables better coverage for less effort, and reduces the possibility of mistakes. Choice: Bundled threat response represents choices the vendor made based on partnerships and commercial interests, not necessarily matching what youÕd choose for your own network.
Flexibility: Ability to bring security services in and out of the equation quickly supports threat response requirements best. Features: Threat mitigation bundled into firewalls usually doesn't match the functionality and features in stand-alone products.
Cost: Long-term costs for UTM will likely be lower than individual point solutions. Separation: Different teams are responsible for different threats, and requiring coordination and agreement between them can be difficult and time-consuming.
Click to see: Enterprise UTM pros and cons

With such dramatic differences between SMB and enterprise requirements, is there a place for enterprise UTM firewalls? The answer is definitely "yes," for these three reasons: reduced complexity, simplified management and increased flexibility.

Reduced complexity

Enterprise network managers have long sought to include additional threat protection, especially intrusion detection/prevention systems (IDS/IPS) functions, both at the core and at the perimeters of their networks. However, the complexity of dropping standalone IDS/IPS boxes into a network has made them wary.

Building the "firewall sandwich," with load balancers surrounding a core of clustered firewalls, is well understood, but trying to scale that sandwich up with another layer of protection dramatically increases architectural complexity and potential instability.

  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Videos

rssRss Feed