Click here to close now.


Related Topics: Cloud Security, Java IoT, Microservices Expo, Open Source Cloud, @CloudExpo

Cloud Security: Article

Why Your NGFW Needs Granular and Contextual Access Control

understand how these evolving feature sets can help contain costs while reducing management complexity

Global information technology networks that are rich in services are typically complex and require hard-to-manage security solutions. The latest versions of next-generation firewalls now offer multiple security layers that can complicate management, particularly as more and more features are added. This complexity can also serve to reduce the effectiveness of controls by obscuring noteworthy events or failing to recognize trends detected by multiple security systems integrated into the overall system. The answer is a common, unified management approach with granular and contextual access control.

Instead of employing multiple and distinct dashboards offering minimal if any integration to manage network security, administrators should be able to access a single dashboard to gain a consistent, unified view across all firewall protected segments. The data must be granular and contextual, empowering IT and network security administrators to execute and control all NGFW operations from a single perspective. And to assure logging of all actions taken and events observed, without regard to operator location.

Consistency is key. This level of administrative awareness and control should be available regardless of modality (physical or virtual) or configuration. Here are five critical control features to look for when evaluating a next generation firewall.

1. Integrated VPN
Secure virtual private network (VPN) connections provide for inter-office and mobile user connectivity to corporate resources. First-tier NGFWs typically provide high-performance remote access with integrated management supporting the use of multiple ISPs to ensure access in the event of link failure. Such solutions typically offer VPN client software to take full advantage of various deployment options. Look for the capability to cluster the firewall configuration to assure availability and session survivability in the event of a firewall appliance update or failure. Flexibility in licensing is also necessary to address burst utilization or pandemic usage requirements. Additionally, support for deep inspection is highly recommended as a necessary precursor to support DLP requirements.

2. Email and Web Security
Email advertising and social media services can flood a network with traffic of little to no business value. And this traffic stream can be a wide conduit for malware. One response is to deploy your NGFWs with additional services such as deep-inspection, web filtering, anti-virus, and anti-spam services. Combining these services under one NFGW umbrella ensures that they are available (especially if the firewall solution is clustered for high availability) and implemented at all relevant chokepoints within an organization. Superior traffic control based on users and groups, as well as contextual awareness of attacks and their use by would-be attackers across the entirety of an organization, improves an organization's resistance to a breach. Furthermore, solutions that support contextual awareness may be able to share details on detected attacks across all firewalls under the same management control, and take broad actions. For example, the actions of an attacker against one firewall may be used to blacklist that attacker across all firewalls of the organization. This amplifying effect is particular pronounced if the NFGW management solution is multi-tenant capable and used to protect multiple divisions or firms.

3. Precise Security Policies
Control over traffic based on a variety of options will enable Network security administrators need great flexibility in granting privileges to employees to perform their jobs. In addition to typical firewall IP Address and port filtering, NGFW solutions also typically support the control of traffic by service (protocol), application, user identity, group affiliation, URL categorization, site reputation, time of day, method(s) of authentication, and context. Precise security policies can provide QoS directives so access control is governed by dynamic business requirements or the availability of underlying communications resources. For example, transaction traffic may be given preferential treatment over social media access by employees, and lower priority traffic is automatically shed if a circuit failure reduces available bandwidth.

4. Integrated Authentication Services
Independent authentication mechanisms often lack integration with the firewall. However, the integration of authentication services with NGFW policies can allow administrators to constrain, track, and log access to services. Such access controls often use a variety of authentication methods including token and virtual token systems. Virtual token applications for mobile phones and tablets reduce costs over traditional key fob tokens. In addition, integration to the NGFW unifies the management of how an individual or members of a group are authenticated.

5. Traffic Management and QoS
Firewalls that feature traffic management and quality of service (QoS) can provide detailed control on what traffic is permitted and at what priority, while assuring end-to-end capacity to meet session requirements. QoS selections such as bandwidth floors and ceilings help to differentiate traffic streams, assuring the streams are treated fairly and not inadvertently precluded in their entirety, or allowed to consume bandwidth to the detriment of other business activities. For isochronous (time sensitive) traffic such as VoIP or video conferencing, the proper handling of long-haul priority directives is necessary to ensure that in-band traffic with specific bandwidth and jitter requirements is accommodated on an as-needed basis.

In addition, traffic management can help triage traffic if sufficient networking bandwidth is unavailable to meet all approved needs. For example, transactions take priority over backups or social media access.

The NGFW can improve the utilization effectiveness of the network and its security posture. It is also a network chokepoint of access from WAN connectivity to remote facilities, mobile employees, and the Internet. Pay attention to all options available with NGFW products and understand how these evolving feature sets can help contain costs while reducing management complexity.

More Stories By Darren Suprina

Darren Suprina is an IT systems designer and security professional with more than 30 years of experience. This has included intellectual property creation, research, development, software and infrastructure design and validation, systems auditing, work as a professional witness, and author.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.

Latest Stories
“All our customers are looking at the cloud ecosystem as an important part of their overall product strategy. Some see it evolve as a multi-cloud / hybrid cloud strategy, while others are embracing all forms of cloud offerings like PaaS, IaaS and SaaS in their solutions,” noted Suhas Joshi, Vice President – Technology, at Harbinger Group, in this exclusive Q&A with Cloud Expo Conference Chair Roger Strukhoff.
SYS-CON Events announced today that G2G3 will exhibit at SYS-CON's @DevOpsSummit Silicon Valley, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Based on a collective appreciation for user experience, design, and technology, G2G3 is uniquely qualified and motivated to redefine how organizations and people engage in an increasingly digital world.
In his session at @ThingsExpo, Tony Shan, Chief Architect at CTS, will explore the synergy of Big Data and IoT. First he will take a closer look at the Internet of Things and Big Data individually, in terms of what, which, why, where, when, who, how and how much. Then he will explore the relationship between IoT and Big Data. Specifically, he will drill down to how the 4Vs aspects intersect with IoT: Volume, Variety, Velocity and Value. In turn, Tony will analyze how the key components of IoT ...
Scott Guthrie's keynote presentation "Journey to the intelligent cloud" is a must view video. This is from AzureCon 2015, September 29, 2015 I have reproduced some screen shots in case you are unable to view this long video for one reason or another. One of the highlights is 3 datacenters coming on line in India.
When it comes to IoT in the enterprise, namely the commercial building and hospitality markets, a benefit not getting the attention it deserves is energy efficiency, and IoT’s direct impact on a cleaner, greener environment when installed in smart buildings. Until now clean technology was offered piecemeal and led with point solutions that require significant systems integration to orchestrate and deploy. There didn't exist a 'top down' approach that can manage and monitor the way a Smart Buildi...
Recently announced Azure Data Lake addresses the big data 3V challenges; volume, velocity and variety. It is one more storage feature in addition to blobs and SQL Azure database. Azure Data Lake (should have been Azure Data Ocean IMHO) is really omnipotent. Just look at the key capabilities of Azure Data Lake:
SYS-CON Events announced today that ProfitBricks, the provider of painless cloud infrastructure, will exhibit at SYS-CON's 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. ProfitBricks is the IaaS provider that offers a painless cloud experience for all IT users, with no learning curve. ProfitBricks boasts flexible cloud servers and networking, an integrated Data Center Designer tool for visual control over the...
“The Internet of Things transforms the way organizations leverage machine data and gain insights from it,” noted Splunk’s CTO Snehal Antani, as Splunk announced accelerated momentum in Industrial Data and the IoT. The trend is driven by Splunk’s continued investment in its products and partner ecosystem as well as the creativity of customers and the flexibility to deploy Splunk IoT solutions as software, cloud services or in a hybrid environment. Customers are using Splunk® solutions to collect ...
You have your devices and your data, but what about the rest of your Internet of Things story? Two popular classes of technologies that nicely handle the Big Data analytics for Internet of Things are Apache Hadoop and NoSQL. Hadoop is designed for parallelizing analytical work across many servers and is ideal for the massive data volumes you create with IoT devices. NoSQL databases such as Apache HBase are ideal for storing and retrieving IoT data as “time series data.”
Clearly the way forward is to move to cloud be it bare metal, VMs or containers. One aspect of the current public clouds that is slowing this cloud migration is cloud lock-in. Every cloud vendor is trying to make it very difficult to move out once a customer has chosen their cloud. In his session at 17th Cloud Expo, Naveen Nimmu, CEO of Clouber, Inc., will advocate that making the inter-cloud migration as simple as changing airlines would help the entire industry to quickly adopt the cloud wit...
As the world moves towards more DevOps and microservices, application deployment to the cloud ought to become a lot simpler. The microservices architecture, which is the basis of many new age distributed systems such as OpenStack, NetFlix and so on, is at the heart of Cloud Foundry - a complete developer-oriented Platform as a Service (PaaS) that is IaaS agnostic and supports vCloud, OpenStack and AWS. In his session at 17th Cloud Expo, Raghavan "Rags" Srinivas, an Architect/Developer Evangeli...
DevOps is gaining traction in the federal government – and for good reasons. Heightened user expectations are pushing IT organizations to accelerate application development and support more innovation. At the same time, budgetary constraints require that agencies find ways to decrease the cost of developing, maintaining, and running applications. IT now faces a daunting task: do more and react faster than ever before – all with fewer resources.
SYS-CON Events announced today that VividCortex, the monitoring solution for the modern data system, will exhibit at the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. The database is the heart of most applications, but it’s also the part that’s hardest to scale, monitor, and optimize even as it’s growing 50% year over year. VividCortex is the first unified suite of database monitoring tools specifically desi...
Organizations already struggle with the simple collection of data resulting from the proliferation of IoT, lacking the right infrastructure to manage it. They can't only rely on the cloud to collect and utilize this data because many applications still require dedicated infrastructure for security, redundancy, performance, etc. In his session at 17th Cloud Expo, Emil Sayegh, CEO of Codero Hosting, will discuss how in order to resolve the inherent issues, companies need to combine dedicated a...
Mobile, social, Big Data, and cloud have fundamentally changed the way we live. “Anytime, anywhere” access to data and information is no longer a luxury; it’s a requirement, in both our personal and professional lives. For IT organizations, this means pressure has never been greater to deliver meaningful services to the business and customers.