Home > How to choose the best firewall for your enterprise
Learning Guide:
EMAIL THIS

How to choose the best firewall for your enterprise

02 Jan 2008 | SearchNetworking.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Learn how to choose the best firewall for your enterprise. This section of the Firewall Guide gives you network firewall purchasing advice, tells you who is responsible for your perimeter security solution and offers a checklist of security risks you must assess before deciding on a firewall or virtual private network (VPN).

Table of contents:
Introduction to firewalls
Types of firewalls
Choosing a firewall
       Who is responsible for firewalls?
       Security risk assessment
       Firewall purchasing advice
Firewall implementation and placement
Firewall management and maintenance
  Who is responsible for firewalls? 

Information security extends beyond networks and has much wider domain coverage. It's always a good practice to have a separate InfoSec department that works with all the business units and departments and helps implement the organization's information security management system (
ISMS). In regards to networks, Infosec works as an architect whereby they create IT security designs, policies, procedures and define IT security controls based on information security standards for network security. A network team takes these as inputs and helps implement and enforce the same on their network infrastructure. An example of this is controlling inbound/outbound access through firewall rules.

This text was excerpted from network security expert Puneet Mehta in his response to the question Who is responsible for firewalls?

  Security risk assessment 

Once you have chosen the team responsible for rolling out your security solution you will have to choose the most appropriate one for your enterprise. The way to determine this is to list and understand the risks your network and enterprise are facing. Risks are threats to your objectives. A proper risk analysis should be done before making any technology decision. When considering adopting firewall/VPN technology, here are some key security risks and standards which should be considered:

To assess risk ask the following questions:

  • What is at risk?
  • What is its value?
  • What are the threats?
  • What is the probability of occurrence?
  • Some of the common security risks are as follows:

  • Single point of failure
  • Loose security policies
  • Support protection
  • Limitation of technology
  • False sense of security
  • Weak encryption
  • Latency
  • Here are some firewall/VPN standards to consider:

  • Open architecture
  • Packet filtration
  • Default to denial
  • Auditing capabilities
  • Access control
  • Logging capabilities
  • Intrusion detection
  • Extended user authentication
  • Secured subnets
  • Strong encryption
  • Network management systems
  • Secure back-up
  • Statefull inspection
  • Real-time traffic monitoring and alerting system
  • Device management
  • Secure tunneling
  • Application layer traffic inspection
  • This information on firewall security risks was was excerpted from expert Puneet Mehta's advice column.

      Purchasing advice 

    Firewall features for SMBs
    Puneet Mehta explains which small and medium-size business (SMB) firewall appliance features are most important.
    To choose the best perimeter security solution, first and foremost, consider the functionality of the firewall. The good news for those deciding between products is that mainstream firewalls all have the same core functions. Each performs stateful inspection packet filtering and allows the implementation of basic perimeter defenses. Security expert Michael Chapple recommends honing in on functional requirements. Ask yourself: Do you need to emphasize network throughput or enhanced security features?

    One major point of differentiation between firewalls is their ability to perform application-layer inspection. (See the Introduction to firewall types section of this guide to learn more about application-layer firewalls.) Many firewalls simply don't have application-layer inspection, while others implement basic functionality (such as URL filtering). Some products, like Secure Computing Corp.'s Sidewinder G2 firewall and F5 Networks' BIG-IP Application Security Manager, have deep application inspection capabilities. These types of firewalls allow for complex application rule bases that limit the types of actions carried out over a connection. For example, you might limit inbound HTTP requests from the Internet to GET commands, while internal users might be able to issue POST commands. This functionality allows you to protect the enterprise against application-based attacks as well as network-based attacks.

    Vendor firewall demos
    These vendor firewall white papers and webcasts demonstrate different firewall appliance features.
    Finally, consider the vendor itself. When investing in a firewall product, you're making a long-term decision. The financial commitment is only the tip of the iceberg; your firewall administrators will invest significant time and energy building and customizing a rule base for that particular product. In general, rule bases are not portable between platforms, so any future platform change will require a substantial commitment of human resources, so it's wise to make sure the vendors on your short list are all stable companies with solid financials. You certainly don't want to get on board a sinking ship.

    This advice was given by Michael Chapple at SearchSecurity.com.

       Continue to our Firewalls implementation and management section →  



    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Networking Tutorials and Technical Guides
    Network user management
    Storage area networks change management primer
    Virtualization change and configuration management primer
    Network change and configuration management primer
    10 Gigabit Ethernet tutorial: Connecting data centers, storage, LAN and beyond
    Application switch testing: An easy RFP guide
    IT networking certifications and career paths for aspiring professionals
    Interop Las Vegas 2009: Special news coverage
    Cisco's Game Face: Can games replace traditional certification prep?
    IP addressing and subnetting explained

    Network Security Best Practices and Products
    Enterprises demand next-generation firewalls with IPS, app visibility
    Preventing hacker attacks with network behavior analysis IPS
    Is there a way to trace my stolen laptop computer?
    Integrating NAC with network security tools
    Should organizations separate technical from administrative security?
    What network equipment is needed to secure a small business LAN?
    Ethical hacking and countermeasures: Network penetration testing intro
    Are you on a domain name system (DNS) blacklist database?
    Rogue access points: Preventing, detecting and handling best practices
    Network security threats solved by risk management: John Pironti explains

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    anti-replay protocol  (SearchNetworking.com)
    dynamic packet filter  (SearchNetworking.com)
    HELLO packet  (SearchNetworking.com)
    packet filtering  (SearchNetworking.com)
    rule base  (SearchNetworking.com)
    stateful inspection  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary




    Network Management features current networking news and in-depth network white papers.
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts