ellen_messmer
Senior Editor, Network World

What you should know about Next Generation Firewalls

News
Dec 1, 20105 mins

Next Generation Firewalls are powerful, if not a bit confusing

 So what is the so-called Next Generation Firewall?

Abbreviated as NGFW, it’s a term popular with vendors, and favored by the Gartner consultancy, to describe newer types of firewalls that go far beyond the older, traditional port-based firewalls to include multi-purpose security defenses and identity-based application controls.

Also read: Is a next-generation firewall in your future?

What would those be?

NGFW is not a scientific term, so there’s fluidity in its use for marketing purposes. But it’s not just marketing hype either. The Gartner consultancy, which has favored the term NGFW for a number of years, is fairly set in what it expects to see in any security equipment calling itself “NGFW.” Gartner’s basic definition is having an impact on vendors deciding to develop more sophisticated firewalls that depart from traditions port-based inspection and controls.

What is Gartner’s notion of NGFW?

In short, Gartner’s “must have” definition for NGFW is:

– Must have standard firewall features such as network address translation, stateful inspection, VPN and be suited for the large enterprise.

– The intrusion-prevention system is “truly integrated” with the firewall.

– There’s an “application-awareness” capability to recognize applications and set controls.

– An “extra-firewall” intelligence can bring in information to help make decisions; examples would be reputation analysis, integration with Active Directory, or useful blocking or vulnerability lists.

So if a vendor says it offers an “NGFW,” should I assume it does all this?

Not necessarily. Again, there’s the marketing aspect that makes using the term NGFW sound good. But many of the established firewall vendors are working to re-tool their firewall product line to meet NGFW expectations. Start-up Palo Alto Networks, which launched in 2007, is widely regarded as the first vendor with a next-generation firewall security appliance, which has had a disruptive effect and gotten the traditional firewall vendors making changes. Palo Alto, too, continues to add features to its gear.

Is NGFW equipment widely used?

No. Gartner estimates less than 1% of secure interconnections are supported through NGFW, though the consultancy predicts that will rise to 35% by 2014. Despite all the hype, the NGFW market is still regarded as emerging.

So what is Unified Threat Management (UTM)?

This is a term coined by IDC to describe a similar concept of a multi-purpose consolidated security device as NGFW. Like NGFW, UTM is also not a scientific term but not totally marketing hype. Although IDC came up with the term UTM, Gartner will bicker over what it means, claiming it refers to a device for the small-to-midsized market. IDC will bicker over what NGFW means. But IDC analyst Charles Kolodgy recently summed up his thoughts in an interesting way by saying, “I very much doubt we will have a market called NGFW, it is just the Firewall market. You can only be next generation for so long.” Some vendors use NGFW and UTM in their marketing. But it’s one of those academic debates that shouldn’t profoundly influence purchasing decisions, especially as there is a lot of product evolution occurring. What should matter is how each so-called NGFW or UTM piece of equipment performs in its designated job in the network.

Are there independent tests of NGFW equipment to help determine this?

Not yet, and vendors acknowledge part of the problem in getting independent labs to take on independent  comparative tests is that the NGFW definition is pretty fluid.

Should buying an NGFW with its consolidated security functions, such as intrusion-prevention or anti-malware filtering, be cost effective over buying separate equipment for separate security functions?

It’s expected to be and it might be, but some early adopters comment that an advantage they see in NGFW is simplified management and operations. At the same time, some say they don’t want to wholly give up using traditional firewalls or standalone IPS, for example, since they’re uneasy with the idea of a wholly one-vendor, one-device approach.

What is the idea behind identity-based application controls?

Most vendors say their NGFW will allow for policy-based controls of more than 1,000 applications, with integration with Microsoft Active Directory a much-mentioned feature. The goal is to determine which applications via the Internet and the Web are allowed to enterprise users. Sometimes it’s more clear which aren’t allowed, such as P2P or some social-networking. Sometimes there’s a slow ramp-up in use of the application-control capability in an NGFW as IT and business managers learn about these types of controls. One question to ask is how the NGFW will protect users when they are using mobile devices outside the firewall.

Should my organization be using a firewall with consolidated IPS, identity-based application controls, etc?

There is a big issue in migrating, with rules, and policy and training staff, and Gartner recommends at least tracking what vendors are doing and where they say their road map is to be able to evaluate what’s out there when firewall negotiations in particular are coming up for discussion.