Saturday, December 29, 2018

Firewall selection consideration

Product

 

Company

 

Certifications

NSS Labs Security
Effectiveness for NGFW - ?%
Effectiveness for BDS - ?%
Effectiveness for IPS -?%
ICSA (Firewall, IPSec, SSL, Antivirus, NIPS, Antispam)
IPv6
VB 100 - ?%
AV Comparative - ?%
Cyber Threat Alliance

# interfaces

GE RJ45
GE SFP
10GE SFP+
Modules Slot

Throughput and Performance

 

Firewall Throughput

This is raw throughput, the measurement of traffic flowing through the firewall without necessarily being subjected to antivirus scans, content filtering, intrusion prevention, data loss checks and similar steps. The figure can also vary by protocol and packet size. Some vendors may cite 1500 Byte TCP whilst others 64 Byte UDP

1518/512/64 byte UDP

IPS Throughput

Gbps(Optimal traffic),  Gbps(Enterprise Mix)

NGFW/UTM Throughput

Gbps(Enterprise Traffic Mix)

SSL Inspection Throughput

 

AV Proxy Throughput

 

Sessions

 

New Sessions per second

 

IPSec VPN

Gbps

Tunnels

No. of Tunnels (e.g. 10000)

SSL VPN

Gbps

Firewall Policies

 

Latency

Microsecond

Remark

When compare between different vendor on performance, it need to confirm they are using the same assumption to provide the figure (e.g. Vendor A will enable all features when testing throughput but Vendor B will disable all features)

Features

 

SD-WAN

 

DNS Filter

 

Web Filter

 

IPS

(No. of signatures)

Anti-Spam

 

Antivirus Gateway

 

Sandbox Integration

Cloud and/or On-perm

Application Control

 

SSL Inspection

443 Port only or ALL ports?

Data Leak Prevention (DLP)

 

Content Filtering

 

Web Application Firewall (WAF)

 

Reverse Proxy

 

Forward Proxy

 

Virtual Domain

 

High Availability

 

3rd Parties Security Solution Integration

 

Power Supply

Single or Dual PSU

Operation

 

Administration Effort

High/Low

Management

Console/Web

Reporting

 

Automation

 

Vendor Support

 

Cost

 

Licensing/Subscription

 

On-going cost /Maintenance cost

  


 

Reference:

https://www.manxtechgroup.com/small-business-firewall-guide/

Print Friendly and PDF
Share/Bookmark

No comments:

Post a Comment