Security devices help improve network performance for key traffic
Juniper is upgrading software for its firewall/VPN device, and intrusion detection and prevention gear to make it easier to apply application-performance policies across corporate networks, the company says.
Slideshow: Take a closer look at Juniper’s ScreenOS 6.0 software, plus the competition from Cisco
The upgrades bring Juniper a step closer to its goal of controlling application performance by integrating its intrusion prevention software with devices that can enforce performance policies. With the upgraded software, if its IPS discovers an instant messaging application, it can enforce policies that, for example, limit bandwidth available to it or block the IM altogether. Until now, the IPS could give customers visibility into application traffic on the network but not enforce policies.
This new capability comes with Juniper’s Screen OS version 6.0 that runs the company’s Integrated Security Gateway (ISG) and Secure Services Gateway (SSG) firewall/VPN gear. It also comes with Intrusion Detection and Prevention (IDP) version 4.1 software for its IDP equipment.
Now, once these devices identify applications, they can take action based on policies. For instance they can rate-limit recreational traffic and to give greater bandwidth to more critical applications. They can also set QoS based on readings of differentiated services code point (DSCP) markings they read in packets.
They can seek viruses within traffic types, such as attachments to instant messages, using integration with Juniper partner products such as Kaspersky anti-virus software.
Over the next two or three years, the company wants to flesh out its software control layer to translate policies to network enforcement. Enforcement points would include personal firewalls, traditional network firewalls, routers, SSL VPN gear and IDP equipment.
Juniper hopes to reach the point where customers can express policies based on user identity, application and quality of service without having to directly relate the policy to the underlying network devices.
Today, Juniper’s NetScreen Security Manager platform can set policy for a group of branch offices, for example, but not implement the policies automatically. A person with knowledge of the network topology has to make sure devices in each branch receive the policy and that policies don’t conflict, Juniper says. So if a new policy has the effect of slowing down a WAN link to the point that it no longer supports a previous QoS policy, the software would trigger an alert.
The software versions give customers a graphical view of traffic on the network, to check, for instance, who is watching Youtube videos. It also gives the ability to then see what else a particular user is doing.
Juniper differs from i competitors such as Cisco and Enterays in that it cannot put application-performance support in enterprise switches and routers because Juniper doesn’t make them. For instance, this week Cisco announced a blade for its 6500 switches that can enforce security and shape traffic.
Screen OS version 6.0 and IDP version 4.1 are available now.
The upgrades bring Juniper a step closer to its goal of controlling application performance by integrating its intrusion prevention software with devices that can enforce performance policies. With the upgraded software, if its IPS discovers an instant messaging application, it can enforce policies that, for example, limit bandwidth available to it or block the IM altogether. Until now, the IPS could give customers visibility into application traffic on the network but not enforce policies.




