Home > Ask the Networking Experts > Network security Questions & Answers > Could you help me with my firewall requirement analysis?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Could you help me with my firewall requirement analysis?

Puneet Mehta EXPERT RESPONSE FROM: Puneet Mehta

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 December 2003
I am working in an IT solution company, and we give customers solutions as per their requirements.

When discussing firewalls -- what do you think are questions that I should ask my customer? If am selling him a Cisco PIX firewall -- how can I get those answers to help me to prepare my BoM. In short how could I size the firewall for the customer?


>
Requirement analysis plays an important role in determining and recommending any technical solution. Apart from the pricing and budgetary factors, the analysis needs to gather the technical information. The major technical information you need are:
  • The size of network (Servers, workstations, switches etc.) at the client site.

  • Network Topology and design.

  • WAN connectivity- Number of sites connected/ Internet/ Connectivity channel and Pipe size.

  • Level of security - Basic packet filtering/NAT/PAT/State inspection.

  • If any security solution already in place?

  • Appliance or Software based solutions - Both of these have their own benefits.

  • Network Traffic Analysis- This is another factor which determines the type and size of firewall.

  • Firewall throughput- Many a times, throughput is also a deciding factor along with security features.

  • IDS/VPN's and other integrated technologies- Most of the companies now lookout for the solution which can provide them all of these as one solution. For example, a client might want to be able to terminate 100 plus VPN connections with a PIX firewall. This might seem okay as a solution, but could be hard on pricing or performance. Here you can suggest some VPN concentrators which take off load from the PIX.

  • Level of Support and training.

  • Product loyalty- This plays an important role. Many companies like to stick with the vendors they have been working with.
  • Answers to the above mentioned questions should give a fair analysis of the requirements.

    Let me know if you need further information.


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network security
    Where can I find Puneet Mehta's most recent network security advice?
    How do VPN concentrators and network access servers (NAS) differ?
    What keeps unauthorized users from accessing my IP address/Internet?
    Controlling network access by MAC address restriction on wired networks
    Retrieve network resources and email after installing ISA Server 2004
    What does a QM FSM error signify on a VPN Concentrator?
    How to block porn with ISA-server firewalls
    Who is responsible for updating network firewalls?
    How to locate the lost IP address of an access point (AP)
    What HIPPA-compliant software would you recommend for online medicine?

    Network Security Monitoring and Analysis
    Application-specific network intrusion detection systems emerge
    Anomaly-based intrusion protection configuration and installation
    How can I calculate perimeter firewall throughput?
    How do I find the application on my network that's dropping packets?
    Integrating NAC with network security tools
    Where can I find a sample security audit report? How can I run my own?
    The firewall remains the network traffic cop, but its role is changing
    Troubleshooting VLANs: How to monitor 802.1q tagged traffic
    Poor data-loss prevention practices almost cost Intel a billion
    How can I block my competitor's IP address range from my website?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    deep packet inspection (DPI)  (SearchNetworking.com)
    FCAPS  (SearchNetworking.com)
    Nessus  (SearchNetworking.com)
    netstat  (SearchNetworking.com)
    port mirroring  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Expert networking advice and tips for IT professionals
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts