It seems to me UTMs are basically stateful firewalls with a few additions and that, for Web 2.0 applications, UTM...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
is obsolete. But what would you define as next-generation firewalls, and would you recommend them, in particular, to protect against Web 2.0 threats?
When stateful inspection firewalls first came on the scene in the 1990s, they revolutionized network security by allowing perimeter protection to move beyond the simple packet-by-packet filtering process used up until that point. Stateful inspection added intelligence and memory to the firewall. Instead of simply making independent decisions each time it encountered a packet, the firewall was now context-aware, able to make decisions based upon the information it had gathered about a connection.
You’re correct in pointing out that unified threat management (UTM) products are basically stateful inspection firewalls with some additional security functionality. You’ll find that these products often consolidate firewall, intrusion prevention, content filtering, antivirus and other security functionality into a single box. While this approach is not often appropriate for a large enterprise, a UTM device can be a very effective product for smaller or midsize enterprises seeking to limit security expenditures.
Next-generation firewalls (NGFW) represent the next major step in the development of firewall technology. I’d actually consider them an advancement from stateful inspection technology, rather than comparing them to UTM devices. A next-gen firewall is designed to combine the functionality of a firewall and an IPS, while adding detailed application awareness into the mix. Like the introduction of stateful inspection, NGFWs bring additional context to the firewall’s decision-making process by providing it with the capability of understanding the details of the Web application traffic passing through it, taking action to block traffic that might exploit Web application vulnerabilities.
UTMs and NGFWs will peacefully coexist in the marketplace for quite some time, because they serve very different markets. While UTMs are targeted at the midsize enterprise that doesn’t generally host Web applications, NGFWs will find their home in large enterprises supporting Web 2.0 applications.
Ask the Expert!
Want to ask Kevin Beaver a question about network security? Submit your questions now via email! (All questions are anonymous.)
Dig Deeper on Network Firewalls, Routers and Switches
Related Q&A from Mike Chapple
The OWASP Top Ten list is not a compliance standard but a set of best practices for enterprises looking to boost Web app security. Here's how to get ...continue reading
A data breach notification policy is important to have, but deciding how to alert customers can be tough. Expert Mike Chapple explains some best ...continue reading
Tokenization technology can be confusing. Expert Mike Chapple explains what the difference is between two types of tokens and how tokenization can ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.