Re: NetScreen / Juniper
Joel Snyder <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Organization | Opus One |
| Message-ID | <[email protected]> |
"pure application proxy" is a marketing buzzword and does not represent real technology. It's the rehashing of a 10-year-old argument that the "pure application proxy" vendors have failed to live up to. Proxy-based firewalls have never taken advantage of the architecture to the extent they claimed they could; packet-filtering (stateful) firewalls have created similar or better controls at the application layer than their proxy-based cousins. I recently did an evaluation of both kinds of products to see which had lived up to their promise and, frankly, the proxy-based firewalls have come only 2 baby steps in the last 5 years while the stateful packet inspection devices have made huge strides, in some cases supplanting the capabilities of the "pure application proxy" folks. The arguments offered by proxy firewalls as to why they're "better" are largely smoke and mirrors, and are not supported by the facts. In many cases, they have appended shitty non-stateful packet filtering firewalls to deal with their miserable proxy performance; in all cases, they have failed to exploit the application-layer visibility except in very specific cases, mostly HTTP. Their SMTP proxies are a joke, generally reducing total system security and trading on general fear that somehow a Microsoft TCP/IP stack is vulnerable just because it came from Microsoft. The proof of the pudding is in the eating, and folks who have built-in application layer visibility and ASIC-level speed (including Check Point, NetScreen and maybe Cisco) are at a distinct advantage. jms Joseph S D Yao wrote: > On Wed, Mar 03, 2004 at 05:30:31AM -0700, Travis Watson wrote: > ... > >>merger gets them much closer. And, with this merger, I would say that it's >>the final death blow to any firewall not on ASIC or running a >>micro-kernel/controller architecture. So the question isn't really "should I >>put an investment in Netscreen or Cisco?" but "should I put an investment >>into any company that is not Netscreen or Cisco?" I just can't imagine how >>Checkpoint, Sidewinder, etc. can be viable products 5 years from now unless >>they significantly re-architect their systems very soon. > > > OK, what kind of pure application proxies are available in an ASIC or a > micro-kernel/controller architecture? > > >>As for Netscreen/Juniper, they aren't leaving anytime soon. > > > They did beat out Cisco in some money thing in the Business section > this week. [I don't follow the money stuff very well.] > -- Joel M Snyder, 1404 East Lind Road, Tucson, AZ, 85719 Phone: +1 520 324 0494 (voice) +1 520 324 0495 (FAX) [email protected] http://www.opus1.com/jms Opus One