Deployment and management with next-generation firewalls

Sam Erdheim · Network Security · 2013

Since the introduction of stateful inspection in the 1990s, firewall administrators and IT security teams have been defining security policies based mostly on the source IP address, destination IP address, and service for a given connection. But as business IT becomes more application-centric, these simpler policies are no longer enough to ensure security. Next-Generation Firewalls (NGFWs) deliver more granular control than traditional firewalls but have their own set of challenges. Just as standard firewalls need to be managed due to the complexity of having thousands of rule sets and the potential for errors, this need increases greatly with NGFWs and their application control and whitelisting capabilities. Sam Erdheim of AlgoSec describes an approach to sizing and deploying NGFWs in users' environments, and to managing firewall policies, to minimise complexity.

Read the paper · More papers on PaperTik