Reviews - Channel Insider
Empowering the next generation Channel
 

Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • Control VM Sprawl, What You Don’t Know Can Hurt You
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily
  • LSI 6Gb/s Portfolio Expands to Include SATA+SAS HBAs
  • Reduce the cost of managing your mobile workers.
  • Find out 7 Ways to Drive Data Center Efficiency
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™



  •  

    The Pros and Cons of Security Appliances

    in Reviews


    Article Rating:starstarstarstarstar / 0
    Article Views: 1001

    Rate This Article:
    Add This Article To:
    Are you deploying security systems? Who isn't? Don't miss eWEEK Labs' analysis of the benefits--and bottlenecks--of all-in-one security appliances.

    This year was the worst ever for worms and viruses, and it doesn't look like the onslaught will slow next year. As IT managers scramble to implement increased protection, integrated security appliances that combine myriad security functions certainly sound like the answer to their prayers. eWEEK Labs' tests show that implementing an integrated appliance will drastically ease ongoing security management and reduce network complexity, yet add a possible bottleneck for performance and availability. Symantec Corp.'s Gateway Security 5400 series and Internet Security Systems Inc.'s Proventia line are the newest entries on the market, with Symantec and ISS hoping to leverage their respective anti-virus and intrusion detection expertise to convince customers that their products are the solution to the bigger security problem.

    One of the biggest drawbacks to these products is that they are a single point of failure in the network architecture. To ensure reliability, these devices must be deployed in tandem, requiring a hefty upfront cash outlay.

    The Swiss Army knife approach is not new, but until now it has been focused on the low end of the market. Appliances targeted at small businesses, from security vendors such as SonicWall Inc. and WatchGuard Technologies Inc., have for years successfully integrated virtual private networking and stateful inspection firewalls with simple content filtering and rudimentary anti-virus capabilities. However, these devices do not provide the performance, reliability and manageability levels that enterprise customers demand for their complex, mission-critical networks.

    Resource Library:

    A new generation of attacks, however, can span multiple packets, requiring the firewall to cache packets and assemble the whole data stream before making policy decisions. This store-and-forward proxy mechanism necessitates drastically different hardware capabilities and tuning parameters than are required for stateful inspection-based engines.

    No matter what the architecture, costs for these appliances can escalate quickly. Although the starting price for the Symantec Gateway 5400 series is about $3,500 for a low-end firewall-only model, beefing up the hardware and layering on additional security services can increase the price to upward of $60,000 for a redundant pair.

    While these integrated appliances show promise, eWEEK Labs recommends getting your house in order before purchasing a multifunction appliance. Such an investment crosses into the purview of several IT entities: The network group, the security group and the corporate messaging group all need to be onboard for the implementation.

    The multifunction appliance should be deployed in conjunction with some existing services; administrators should continue to maintain their internal anti-virus and network-based intrusion detection/intrusion prevention architectures. However, content and network filtering devices will be replaced outright, which may be a battle if a particular device is already working well.

    Click here for the full story.

    Technical Analyst Andrew Garcia can be reached at andrew_garcia@ziffdavis.com.





    Discuss The Pros and Cons of Security Appliances
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Reviews Articles          >>> More By Andrew Garcia
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    Enterprise Mobility Zone
    The Enterprise Mobility Zone (EMZ) blog is a tool designed to help senior IT executives discuss, create and deploy next-generation mobile strategies in their organizations.
    Go beyond yesterday's tactical approach to mobility!
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com