As I have mentioned before, back in September we held our Annual Security and disaster recovery event at Miller Park. Today I would like to highlight security solutions from Palo Alto networks.
Palo Alto makes a next generation firewall. Most traditional firewalls block based on a port basis. This worked will back in the 90's, but not so well in today's environment. Applications have evolved with numerous client server applications running over port 80. With those applications come threats. Let's take facebook as an example. Not only can you post messages, you can also chat. A traditional firewall would be unable to find the chat application.
Another issue with traditional firewalls is preventing Instant Messenger. Instant Messenger programs are setup to port crawl (search for an open port). Even if you block the standard port, it could still find a way out.
Palo Alto identifies the application without the need to worry about the port. Palo Alto can identify the application by an ID. They have well over 500 applications identified, from Microsoft Updates, World of War craft and various others. You can simply stop the application.
Virus scanning is another feature missing is most traditional firewalls. Some of them are solving it by plugging in a third party solution. Palo Alto can scan incoming traffic for viruses, ensuring all traffic is clean.
User Authentication and Identification is another important function. With User Authentication you can assign a user to a URL filtering and a single rule in a firewall rulebase. If the user moves to a different workstation, the firewall rule set follows them. This is good for logging and also gives you some great flexibility in creating a rule set.
To check our presentation on To Palo Alto next generation firewall'sat. http://www.jsotechnology.com/_presentations/Miller%20Park/Microsoft%20PowerPoint%20-%20PALO%20ALTO%20JSO_day.pdf
Labels: Palo Alto