tgreene
Executive Editor

Multi-function boxes take off

News
Jun 13, 20056 mins

Individual job-specific security devices have fans, but days might be numbered.

As the number of security technologies grows – firewall, anti-virus, content filtering, intrusion detection and others – some vendors suggest it makes sense to load all these platforms on a single device to save capital and operational costs, and perhaps even to improve security.

The flip side is that these boxes might represent a single point of failure in the network and that the individual security functions might not represent the best in their category.

Nevertheless, more vendors are offering products in this category, with recent additions ranging from network leader Cisco to start-up NetworkD. Other vendors include Crossbeam, Fortinet, Juniper, Sonic Wall, Symantec, Secure Computing and ServGate. A recent study by IDC says it expects even more vendors to enter this market, which is expected to boom over the next few years. In 2003, the total sales in this category were $105 million, according to IDC, but that is expected to grow to $3.5 billion by 2008. Sales of multi-function platforms will cut into the revenues that today go to firewall/VPN appliances, IDC says.

This growth is in part because these multi-function products, which in many cases grew out of firewall technologies, are maturing and overcoming some of the shortcomings they may have had earlier, experts say. For instance, some suffered performance hits when all security platforms were turned on, says Zeus Kerravala, an analyst with The Yankee Group. “They didn’t scale very well because they were a firewall, and they added other security to it later. But now they have a lot of processing power to handle all functions,” he says.

Rampant skepticism?

Despite effort by vendors to deal with shortcomings, end users are still skeptical, according to a poll of 653 IT managers from businesses with at least 1,000 employees. Fewer than one in five prefer the stand-alone, multi-function security devices; most of them prefer multiple, single-function appliances, according to an unpublished study by Forrester Research.

“That’s mostly because of the immaturity of the all-in-one type devices,” says Rob Whiteley, an analyst with Forrester. “What’s been out there really didn’t have sufficient horsepower to handle all-in-one. It defeats the purpose of security if your box fails and thus is more of a risk that it ever was.”

For this reason, Summit Information Systems in Corvallis, Ore., dropped a Nokia IP440 firewall/VPN/intrusion-protection platform, says Ken Pearson, network manager for the firm. “I had an instance where we were running [multiple functions] on the same platform and it flat ran out of horsepower. I had to split the functions to keep up,” he says. The company now uses separate firewall, intrusion-detection and intrusion-prevention platforms. “It’s a bit more trouble, but it’s worth it.”

Provell, a marketing firm in Minneapolis, agrees that many individual devices are preferable, but not because of performance slowdowns. It uses multiple systems to backstop each other, says William Wells, the company’s technical support manager.

For instance, Provell’s Internet router blocks certain ports, and its firewall is configured to block the same ones. “I’ve always taken the approach that anything coming in from outside should pass through at least two distinct security systems which use different approaches and complementary rules. While both may block or allow the same ports, they do so in a different manner,” Wells says.

Not everyone feels the same way. “The probability of human error is geometrically higher with a bunch of single function boxes,” says Roger O’Daniel, a network and security consultant also in Minneapolis.

“A high-quality multi-function box with built-in redundancy and powered by high-quality [uninterruptible power supply] will do a better job than a bunch of single-function boxes that get into each other’s way,” he adds.

Taking the time

Some customers, though, are unwilling to spend the time to get independent security platforms to work together. For instance, Yellow Book USA uses many single-function devices so security staff can focus on specific tasks and the security parameters associated with it, says Bill Flusek, Yellow Pages’ enterprise infrastructure architect.

“It does mean that you have more devices, and I suppose the chance of a misconfiguration is higher that way, but it may still outweigh the potential problems that exist with several functions with different security needs within a single system,” he says.

Security bundled or a la carte?

Multi-function security platforms combine firewalls, VPN, anti-virus, intrusion- protection and other applications, but some users prefer to buy stand-alone products instead. There are trade-offs.
ProsCons
Simplifies administration of security.Single point of failure.
Requires fewer company resources to support.Not best of breed for all applications.
Deal with a single vendor.More complex therefore more potential security flaws.
Broad range of security for less than individual platforms cost.Might lack processing power to keep all applications running at wire speed.

The Yankee Group’s Kerravala says that vendors working out management that supports a single-policy engine that applies a central policy across all the platforms’ different functions are lifting worry.

Another concern is that if a multi-function box fails, the network is left without protection, but Whiteley says that objection is being overcome as these devices mature.

The failure of a single function won’t bring down the whole box and they can be configured with two running in hot-failover mode so if a process on one fails, the other picks it up immediately.

“You’re going to find you get a much greater level of reliability and security at a much more affordable cost,” he says. “It allows you not only to deploy it in places like headquarters but it allows you to drop-ship these preconfigured devices to branch offices and employ a certain amount of security that was never present there before.”

While many customers weigh multi-function vs. single-function devices, a third possibility is that security can be embedded in network devices such as switches and routers, Whiteley says. According to Forrester’s survey, this option is most popular in networks of businesses with more than 20,000 employees. “It looks like that’s because they have these more expensive things like a [Cisco] Catalyst switch, so they can afford to put a PIX [firewall] blade in it. They can afford to have a more holistic view of network security.”

Ultimately, though, Whiteley says that network management platforms with central security policy engines embedded will be able to deliver the policies to whatever devices are installed in the network. “Eventually it’s going to be a network management more than anything else,” he says.