Re: NetScreen / Juniper

Joel Snyder <[email protected]>
Newsgroups gmane.comp.security.vpn
Organization Opus One
Message-ID <[email protected]>
"pure application proxy" is a marketing buzzword and does not represent 
real technology.  It's the rehashing of a 10-year-old argument that the 
"pure application proxy" vendors have failed to live up to.  Proxy-based 
firewalls have never taken advantage of the architecture to the extent 
they claimed they could; packet-filtering (stateful) firewalls have 
created similar or better controls at the application layer than their 
proxy-based cousins.

I recently did an evaluation of both kinds of products to see which had 
lived up to their promise and, frankly, the proxy-based firewalls have 
come only 2 baby steps in the last 5 years while the stateful packet 
inspection devices have made huge strides, in some cases supplanting the 
capabilities of the "pure application proxy" folks.

The arguments offered by proxy firewalls as to why they're "better" are 
largely smoke and mirrors, and are not supported by the facts.  In many 
cases, they have appended shitty non-stateful packet filtering firewalls 
to deal with their miserable proxy performance; in all cases, they have 
failed to exploit the application-layer visibility except in very 
specific cases, mostly HTTP.  Their SMTP proxies are a joke, generally 
reducing total system security and trading on general fear that somehow 
a Microsoft TCP/IP stack is vulnerable just because it came from Microsoft.

The proof of the pudding is in the eating, and folks who have built-in 
application layer visibility and ASIC-level speed (including Check 
Point, NetScreen and maybe Cisco) are at a distinct advantage.

jms


Joseph S D Yao wrote:

> On Wed, Mar 03, 2004 at 05:30:31AM -0700, Travis Watson wrote:
> ...
> 
>>merger gets them much closer.  And, with this merger, I would say that it's 
>>the final death blow to any firewall not on ASIC or running a 
>>micro-kernel/controller architecture.  So the question isn't really "should I 
>>put an investment in Netscreen or Cisco?" but "should I put an investment 
>>into any company that is not Netscreen or Cisco?"  I just can't imagine how 
>>Checkpoint, Sidewinder, etc. can be viable products 5 years from now unless 
>>they significantly re-architect their systems very soon.
> 
> 
> OK, what kind of pure application proxies are available in an ASIC or a
> micro-kernel/controller architecture?
> 
> 
>>As for Netscreen/Juniper, they aren't leaving anytime soon.
> 
> 
> They did beat out Cisco in some money thing in the Business section
> this week.  [I don't follow the money stuff very well.]
> 

-- 
Joel M Snyder, 1404 East Lind Road, Tucson, AZ, 85719
Phone: +1 520 324 0494 (voice)  +1 520 324 0495 (FAX)
[email protected]    http://www.opus1.com/jms    Opus One
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.