Commentary
$28 Million For An Old Idea-Part 1
You have to admire the chutzpah of startup Palo Alto Networks. The company has raised $28 million to sell a "next-generation" firewall based on ideas that are 20 years old.You have to admire the chutzpah of startup Palo Alto Networks. The company has raised $28 million to sell a "next-generation" firewall based on ideas that are 20 years old.Here's how it breaks down. Palo Alto Networks (PAN) says its new firewall can identify more than 400 applications, including Web applications, that traditional firewalls can't. Using the "new" technology, PAN can spot IM, Web mail, P2P, and other traffic. These apps are common vectors for malware and data leakage, can steal bandwidth from business apps, and may disrupt employee productivity.
PAN says its firewalls let administrators create fine-grained policies to deal with these applications, such as allowing Yahoo IM but no others. It also can detect attacks in these traffic streams. By contrast, stateful inspection firewalls are more blunt. If a stateful inspection firewall allows HTTP via port 80, any application that tunnels inside the protocol and uses that port will get into or out of the enterprise, whether security admins like it or not.
More SMB Insights
White Papers
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
Reports
- Design on a Dime: VPNs for Small and Midsize Businesses
- SaaS 2011: Adoption Soars, Yet Deployment Concerns Linger
Webcasts
- Effective IT Inventory and Asset Management: From Quagmire to Quick Fix
- Maximize ROI with Database Consolidation onto Private Clouds
PAN's approach is both valid and useful, but here's where the chutzpah comes in. Co-founder Nir Zuk was a principal engineer for Check Point Software and a pioneer of stateful inspection technology. Check Point spent a great deal of effort badmouthing a competing firewall technology, the application proxy. Application proxy firewalls essentially do the same thing that PAN does -- identify a variety of applications, inspect them, and enforce granular policies on them.
However, back in the 1990s Check Point and its stateful inspection brethren (such as Cisco PIX) did such a great job of denigrating the application proxy firewall that today its share of the firewall market looks like a rounding error.
There are major technological differences between PAN and application proxies (and I'll get to those in a subsequent post), but I find it ironic that Zuk's newest venture is based on concepts Check Point tried to marginalize so many years ago.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
Research & Reports
SMEs and the Cloud: How Much Is Too Much?
This exclusive downloadable research report examines how outsourcing certain IT functions to a service provider can pay off for small and midsize businesses, even more than for large enterprises. But go too far into the cloud, and you may suffer in terms of maintaining agility and responsiveness to market forces.
Secure Design on a Dime: Our Top 5 Best Practices for SMEs
This exclusive downloadable research report details the security tools that small shops need, at a minimum, to prepare for the increasingly complex security and compliance environment that exists today and the top 5 ways growing businesses can stretch their IT budgets.
Current SMB Issue
- 6 Steps To Modern Data Center Architecture: A phased data center upgrade makes technical and financial sense. Randy George suggests six steps to follow.
- Manage Your Managed Service Provider: Michael A. Davis discusses strategies for how the make your MSP work for you.
- And much more!
SMB Whitepapers
- Building a Business-Ready Mobile Infrastructure
- Shared Storage for SMB Server Bundles
- No Compromise, Cost Effective, VMware Storage for the SMB
- Three unique technologies provide users with a truly modern storage experience
- Rethinking Backup and Recovery: Disk vs. Tape
- Server Room Solutions: How small to midsize IT businesses can make their IT budgets appear larger than they are
- Top Three Microsoft Exchange Concerns and EMC Solutions



