Home > Security News > IT pros find corporate firewall rules tough to navigate
Security News:
EMAIL THIS
COLUMN

IT pros find corporate firewall rules tough to navigate

By Eric Ogren
15 Jun 2009 | SearchSecurity.com


Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Corporate firewalls usually contain a security-Pandora's box of rules, representing prioritized sequences of allow or deny decisions that only the most brave security operator dares to modify. Removing or re-sequencing firewall rules runs the risk of blocking approved business communications or of opening a hole exposing the business to unauthorized traffic.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

It is near impossible for a human to manually audit firewall rules across the enterprise to reduce risk, optimize firewall device performance, and streamline data paths through routers, switches and firewalls. Security teams are turning to firewall management tools to perform security audits of the infrastructure and automate operational control of the firewalls.

The total annual market size for privately held firewall management vendors is well below $100 million, though the vendors are posting healthy year-over-year increases in their business. Companies providing firewall rules management include AlgoSec Inc., Athena Security Inc., Firemon, RedSeal Systems Inc., Secure Passage LLC, Skybox Security Inc. and Tufin Software Technologies Ltd. Firewall management software can help ease the burden since corporate networks are far too complex to navigate manually. Network administrators use tools to provide a roadmap of network flows to perform periodic security audits of the infrastructure, and to control the workflow of change to firewall rules to ensure consistency across the network.
Firewall rules:
irewall management tools aid configuration, compliance: Firewall management is critical in today's regulatory climate. Companies looking to streamline firewall management will look to tools from several vendors.

Choosing the Right Web Application Firewall: PCI DSS is requiring companies to buy Web application firewalls. We'll show how you how to pick the WAF that's right for you.

When evaluating a firewall management vendor check out how they satisfy these primary requirements:

  • Segment sensitive applications from general business traffic. For example, PCI mandates firewalls are configured to partition credit card processing systems from the rest of the network to prevent leakage of consumer data. Corporate policies also may dictate isolation of datacenters or network operating centers. IT needs to tightly configure the relationships between firewalls to allow only application data and to block all other access, and then periodically verify there has been no drift in the rules that would create a security risk.

  • Implement workflow controls and operational processes to ensure consistency across the network. Security teams implementing process control over firewall rule changes are finding operational benefits in fewer service calls, less time to meet firewall service calls, quality improvements through peer reviews and approvals, and easier maintenance of a compliant state.

  • Gain a consolidated business view across a multivendor firewall environment. Some firewalls have thousands of atomic-level rules while other vendors support fewer, more comprehensive rule sets. It may be challenging to rationalize the security policy expressed in rules across firewall devices from different vendors such as Check Point Systems Inc., Cisco Systems Inc. and Juniper Networks Inc.

  • Improve network performance and effectiveness by coordinating firewalls, routers and switches. Every rule that needs to be checked in a firewall, router or switch adds latency. For instance, it is not uncommon for firewalls to contain rules that must be checked, even though an upstream router decision renders the firewall rules superfluous because the affected traffic can never reach the firewall. Organizations optimizing the performance of network devices need tools to compare the configurations of firewalls, routers and switches to identify rules that can be safely removed.

The firewall management vendors may tout that removing rules from firewalls provides a performance boost that also extends the life of the firewall device. However, most organizations prefer to buy a faster firewall device rather than run the risk of removing rules that turn out to be needed. The firewall management market may turn into technology that leverages network security audit services with product features shifting to operational workflow controls and diagnostic efficiencies. Enterprises with complex networks should use tools to check that firewall configuration rules are not creating security holes.


Eric Ogren is founder and principal analyst of the Ogren Group, which provides industry analyst services for vendors focusing on virtualization and security. Prior to founding the Ogren Group, Eric served as a security industry analyst for the Yankee Group and ESG. Ogren has also served as vice president of marketing at security startups Okena, Sequation and Tizor. He can be reached by sending an email to eric@ogrengroup.com.

Tags: Network Firewalls, Routers and SwitchesApplication Firewall SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network Firewalls, Routers and Switches
How to prepare for a secure network hardware upgrade
Best Network Firewall Products
What is the difference between static and dynamic network validation?
Screencast: Smoothwall offers firewall defense in lean times
New Cisco IOS bugs pose tempting targets, says Black Hat researcher
How to implement virtual firewalls in a complex network infrastructure
How to manage network bandwidth with distributed ISP bandwidth
Firewall rule management best practices
Should enterprises be running multiple firewalls?
What are the disadvantages of proxy-based firewalls?

Application Firewall Security
Web application firewall use goes beyond compliance, company finds
Best Application Security Products
Common PCI questions: Web application firewalls or source code review?
PCI compliance requirement 1: Firewalls
Comparing an application proxy firewall and a gateway server firewall
Citrix virtual desktop, app delivery controller includes security benefits
How to choose between source code reviews or Web application firewalls
Check Point adds virtual firewall appliance
Web application firewall deployments gain traction
Positive changes coming to ModSecurity

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bastion host  (SearchSecurity.com)
firewall  (SearchSecurity.com)
Firewall Builder  (SearchSecurity.com)
screened subnet  (SearchSecurity.com)
virus  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts