What’s required of a next-generation WAN firewall

Opinion
Jan 17, 20083 mins

* Features that we can expect to see in the next generation of WAN firewalls

Last time, we discussed some of the limitations of the current generation of WAN firewalls, such as the fact that they are blind to the growing number of applications that transit port 80. Today, we’ll describe some additional limitations of the current crop of firewalls and detail some of the features that you can expect to see in the next generation.

Last time, we discussed some of the limitations of the current generation of WAN firewalls, such as the fact that they are blind to the growing number of applications that transit port 80 (see our other newsletter “Ignore the port 80 black hole at your peril”). Today, we’ll describe some additional limitations of the current crop of firewalls and detail some of the features that you can expect to see in the next generation.

To be considered a next-generation product, a firewall will need to eliminate the blind spots that are associated with the current crop. To make this happen, a firewall must be able to look beyond the IP header 5-tuple into the payload of the packet to find application identifiers. Unfortunately, there is no standard way of identifying applications. This means there must be an extensive library of application signatures that includes identifiers for all commonly used applications. This functionality will allow the firewall to examine the traffic that is transiting port 80 and will position the IT organization to enforce a granular security policy.

Another limitation of the current generation of firewalls is how it handles HTTP traffic. Since the payload of these packets is encrypted with SSL, the traditional firewall cannot use DPI to determine if the traffic either poses a threat or violates enterprise policies for network usage. A next generation firewall needs the ability to decrypt SSL-encrypted payloads to look for application identifiers/signatures. Once this inspection is performed and policies applied, allowed traffic would be re-encrypted before being forwarded to its destination.

We asked the senior director of IT at a medical institution about the limitations of the current generation of firewalls. He stated that traditional firewalls do not provide application layer filtering so if you are attacked above Layer 3 “you are toast”. He also stated that his organization had been looking at adding other security functionality such as IDS, IPS and NAC (network access control). What he wanted, however, was to avoid the complexity of having a large number of security appliances. He preferred to have a “firewall on steroids” provide all this functionality. That highlights another requirement of next generation firewalls: multi-gigabit throughput.

More information on this topic can be found in our report: “The Next Generation Firewall – The Policy and Security Control Point”.

Jim has a broad background in the IT industry. This includes serving as a software engineer, an engineering manager for high-speed data services for a major network service provider, a product manager for network hardware, a network manager at two Fortune 500 companies, and the principal of a consulting organization. In addition, Jim has created software tools for designing customer networks for a major network service provider and directed and performed market research at a major industry analyst firm. Jim’s current interests include both cloud networking and application and service delivery. Jim has a Ph.D. in Mathematics from Boston University.

More from this author