33
Next Generation Firewalls: Ready or Not David Strom AITP St. Louis March 2014 [email protected] 1

Next generation firewalls: ready or not

Embed Size (px)

DESCRIPTION

Speech for AITP St Louis chapter March 2014

Citation preview

Page 1: Next generation firewalls: ready or not

1

Next Generation Firewalls: Ready or Not

David StromAITP St. Louis March 2014

[email protected]

Page 2: Next generation firewalls: ready or not

2

Who am I?

• Long time tech journalist, product reviewer and speaker

• IT manager from the dawn of the PC era• Former editor-in-chief at Network Computing,

Tom’s Hardware.com• Author of two books on computer networking• Based here

Page 3: Next generation firewalls: ready or not

3

Agenda

• Next Gen distinguishing characteristics• Issues with next gen deployment• UTM pro and con• Advanced persistent threat tools

Page 4: Next generation firewalls: ready or not

4

The older firewall generation

Page 5: Next generation firewalls: ready or not

5

Cisco ASA: what it used to be like

Page 6: Next generation firewalls: ready or not

6

Next Gen distinguishing characteristics

• Applications granularity and awareness• Integrated IPS• IP Reputation management• Geolocation

Page 7: Next generation firewalls: ready or not

7

Page 8: Next generation firewalls: ready or not

8

Cisco ASA applications granularity

Page 9: Next generation firewalls: ready or not

9

New Cisco ASA Dashboard

Page 10: Next generation firewalls: ready or not

10

And another Cisco view

Page 11: Next generation firewalls: ready or not

11

Palo Alto Networks “Applipedia”

Page 12: Next generation firewalls: ready or not

12

Page 13: Next generation firewalls: ready or not

13

Reputation management

Page 14: Next generation firewalls: ready or not

14

Page 15: Next generation firewalls: ready or not

15

McAfee Enterprise Firewall geo-location feature

Page 16: Next generation firewalls: ready or not

16

Deployment issues

• Next gen does things differently from old school:– NAT– QoS– Outbound vs. inbound rule focus

Page 17: Next generation firewalls: ready or not

17

Page 18: Next generation firewalls: ready or not

18

Understanding app ID implications for users

Page 19: Next generation firewalls: ready or not

19

One obstacle to switching to next-gen

Page 20: Next generation firewalls: ready or not

20

Network documentation isn’t current

Page 21: Next generation firewalls: ready or not

21

Handling VMs still an issue

Page 22: Next generation firewalls: ready or not

22

Lots of VM security products…

Page 23: Next generation firewalls: ready or not

23

Catbird’s compliance radar graph

Page 24: Next generation firewalls: ready or not

24

Page 25: Next generation firewalls: ready or not

25

Infrastructure misuse

Page 26: Next generation firewalls: ready or not

26

What about UTMs?

• Pro:– A lot of protection for the $ nowadays

(Juniper/Check Point)– One box does it all

• Con:– Complex licensing issues– Can get expensive if you have high bandwidth

needs– Latency can kill you if you turn on Anti-Virus

Page 27: Next generation firewalls: ready or not

27

Juniper SRX dashboard

Page 28: Next generation firewalls: ready or not

28

SonicWall

Page 29: Next generation firewalls: ready or not

29

Page 30: Next generation firewalls: ready or not

30

Watchguard UTM

Page 31: Next generation firewalls: ready or not

31

APT tools

• Try to catch the bad guys before they actually deploy their payloads, such as from Norse Corp. (local boys) and Cyphort

Page 32: Next generation firewalls: ready or not

32

Page 33: Next generation firewalls: ready or not

33

For more info

[email protected]• Twitter: @dstrom• http://strominator.com• TechTarget article: http://bit.ly/1dISmx4• Network World review of UTMs:

http://bit.ly/1fJtmHE