SlideShare a Scribd company logo
Next Generation (NG) Firewalls
•   Firewall history
•   But what about???
•   Complexity creep
•   NG firewalls
Firewall history
• Routers
  • Access control lists (non-stateful)
• Firewalls
  • Stateful firewalls appeared mid 90s
      • Fairly simple databases (state tables)
      • NAT/PAT complicates things (state tables + src & dst ports)
  • Work at Layer 4 in the OSI 7 layer model
       3.     Network (IP/ICMP)
       4.     Transport (host-to-host flow control TCP/UDP)
• From wikipedia (sorry!):
“Early attempts at producing firewalls operated at the Application
Layer, which is the very top of the seven-layer OSI model. This method
required exorbitant amounts of computing power and is rarely used in
modern implementations.”
But what about???
• AKA functionality creep
  •   Intrusion Detection/Prevention Systems
  •   Virtual Private Networks (S2S, C2S)
  •   Application control
  •   Web Proxy
  •   Anti-virus/malware
  •   Identity awareness
Complexity creep
•   All separate devices – creates problems…
•   Network throughput
•   Resilience
•   Cost (Capital and Revenue)
•   Complexity
    • Troubleshooting
    • Down-time
NG Firewalls
• Massively powerful switch/routers
• Massively powerful analysis engines
• Architected to analyse multiple of 10Gigabits of traffic in real-
  time
  • The type of access-list is entirely different
  • Instead of:
      • [IP Address A] can access [IP Address B] on [Port Y]
  • We can write:
      • [Users] in the [Finance Group] can access [Finance systems] during
        [08.00 until 18.00]
      • [All Students] on [IT Suite PCs] can only access [Social networking
        sites] between [17.00 and 09.00]
      • [Anyone] using [bittorrent] can only [upload] at [50kpbs]
      • [Anyone] using [www] (if not previously known) must [authenticate]

More Related Content

PDF
OpenNebulaConf2017EU: Hyper converged infrastructure with OpenNebula and Ceph...
OpenNebula Project
 
PDF
OpenNebulaConf2017EU: Providing cloud and Managed Hosting Environment by Mich...
OpenNebula Project
 
PPT
Dynamic routing in microservice oriented architecture
Daniel Leon
 
PPTX
Cloud Computing Security
Anshul Patel
 
PDF
Go, Swarm and DevOps vs The Mighty Monolith
Igor Karpovich
 
PDF
OpenNebula Conf 2014 | Bootstrapping a virtual infrastructure using OpenNebul...
NETWAYS
 
PDF
OpenNebula Conf | Lightning talk: Managing a Scientific Computing Facility wi...
NETWAYS
 
PDF
rOCCI – Providing Interoperability through OCCI 1.1 Support for OpenNebula
NETWAYS
 
OpenNebulaConf2017EU: Hyper converged infrastructure with OpenNebula and Ceph...
OpenNebula Project
 
OpenNebulaConf2017EU: Providing cloud and Managed Hosting Environment by Mich...
OpenNebula Project
 
Dynamic routing in microservice oriented architecture
Daniel Leon
 
Cloud Computing Security
Anshul Patel
 
Go, Swarm and DevOps vs The Mighty Monolith
Igor Karpovich
 
OpenNebula Conf 2014 | Bootstrapping a virtual infrastructure using OpenNebul...
NETWAYS
 
OpenNebula Conf | Lightning talk: Managing a Scientific Computing Facility wi...
NETWAYS
 
rOCCI – Providing Interoperability through OCCI 1.1 Support for OpenNebula
NETWAYS
 

What's hot (16)

PPTX
Linux kit meetup_v1.0.0
Anshul Patel
 
PPTX
linkerd: The Cloud Native Service Mesh
Dario Simonetti
 
PDF
Performant and Resilient Storage: The Open Source & Linux Way
OpenNebula Project
 
PPTX
Cloud Origins: How OpenStack became the natural evolution of the internet and...
Cloud Native Day Tel Aviv
 
PPTX
My internwork
V C
 
PPTX
Node Architecture.pptx
Ahmed Hassan
 
PPTX
The Nextcloud Roadmap for Secure Team Collaboration
Univention GmbH
 
PDF
Bringing Private Cloud computing to HPC and Science - EGI TF tf 2013
Ignacio M. Llorente
 
PDF
UbiquiTalk - An Infrastructure for Ubiquitous Computing (ESUG 2006)
Noury Bouraqadi
 
PPTX
IoT Day 2017 - Starter Kit SmartEnergy
Lorenzo Maiorfi
 
PDF
Art of nodejs
Shadaï ALI
 
PPT
InfiniBand in the Lab (vSphere 5.5) VMworld 2013 Barcelona vBrownbag Tech Talk
Erik Bussink
 
PPTX
Cldfnd chapter1-4
Mostafa PourMonazah
 
PPT
Civil War: LXD vs Docker
OpenNebula Project
 
PDF
Modern Computing System & Beyond
Nuwan Bandara
 
PDF
Planidoo & Zotonic
David de Boer
 
Linux kit meetup_v1.0.0
Anshul Patel
 
linkerd: The Cloud Native Service Mesh
Dario Simonetti
 
Performant and Resilient Storage: The Open Source & Linux Way
OpenNebula Project
 
Cloud Origins: How OpenStack became the natural evolution of the internet and...
Cloud Native Day Tel Aviv
 
My internwork
V C
 
Node Architecture.pptx
Ahmed Hassan
 
The Nextcloud Roadmap for Secure Team Collaboration
Univention GmbH
 
Bringing Private Cloud computing to HPC and Science - EGI TF tf 2013
Ignacio M. Llorente
 
UbiquiTalk - An Infrastructure for Ubiquitous Computing (ESUG 2006)
Noury Bouraqadi
 
IoT Day 2017 - Starter Kit SmartEnergy
Lorenzo Maiorfi
 
Art of nodejs
Shadaï ALI
 
InfiniBand in the Lab (vSphere 5.5) VMworld 2013 Barcelona vBrownbag Tech Talk
Erik Bussink
 
Cldfnd chapter1-4
Mostafa PourMonazah
 
Civil War: LXD vs Docker
OpenNebula Project
 
Modern Computing System & Beyond
Nuwan Bandara
 
Planidoo & Zotonic
David de Boer
 
Ad

Similar to Next generation (ng) firewalls (20)

PPTX
Security analytics
Simon Bennett
 
PPTX
Moving to software-based production workflows and containerisation of media a...
Kieran Kunhya
 
PDF
Using IT Equipment in Live Broadcast
Kieran Kunhya
 
PPTX
Building the Internet of Things with Thingsquare and Contiki - day 1, part 3
Adam Dunkels
 
PPTX
Basic Foundation For Cybersecurity
Mohammed Adam
 
PPTX
Tracking the International Space Station with Commodore Computers
Leif Bloomquist
 
PPTX
1. RINA motivation - TF Workshop
ARCFIRE ICT
 
PDF
Html5 web sockets - Brad Drysdale - London Web 2011-10-20
Nathan O'Hanlon
 
PDF
From Device to Data Center to Insights
DataWorks Summit/Hadoop Summit
 
PPTX
From Device to Data Center to Insights: Architectural Considerations for the ...
P. Taylor Goetz
 
PPTX
Smart Object Architecture
Hannes Tschofenig
 
PDF
Matrix, The Year To Date, Ben Parsons, TADSummit 2018
Alan Quayle
 
PDF
Software defined networking: Primer
Muhammad Moinur Rahman
 
PDF
XPDS14: OpenXT - Security and the Properties of a Xen Virtualisation Platform...
The Linux Foundation
 
PDF
Distributech_Presentation DTECH_2013
Dorian Hernandez
 
PPTX
Intro RINA
ARCFIRE ICT
 
PPTX
5. IO virtualization
Hwanju Kim
 
PDF
Scalable Service-Oriented Middleware over IP
Dai Yang
 
PDF
Network Stack in Userspace (NUSE)
Hajime Tazaki
 
PDF
Grid middleware is easy to install, configure, secure, debug and manage acros...
Paul Brebner
 
Security analytics
Simon Bennett
 
Moving to software-based production workflows and containerisation of media a...
Kieran Kunhya
 
Using IT Equipment in Live Broadcast
Kieran Kunhya
 
Building the Internet of Things with Thingsquare and Contiki - day 1, part 3
Adam Dunkels
 
Basic Foundation For Cybersecurity
Mohammed Adam
 
Tracking the International Space Station with Commodore Computers
Leif Bloomquist
 
1. RINA motivation - TF Workshop
ARCFIRE ICT
 
Html5 web sockets - Brad Drysdale - London Web 2011-10-20
Nathan O'Hanlon
 
From Device to Data Center to Insights
DataWorks Summit/Hadoop Summit
 
From Device to Data Center to Insights: Architectural Considerations for the ...
P. Taylor Goetz
 
Smart Object Architecture
Hannes Tschofenig
 
Matrix, The Year To Date, Ben Parsons, TADSummit 2018
Alan Quayle
 
Software defined networking: Primer
Muhammad Moinur Rahman
 
XPDS14: OpenXT - Security and the Properties of a Xen Virtualisation Platform...
The Linux Foundation
 
Distributech_Presentation DTECH_2013
Dorian Hernandez
 
Intro RINA
ARCFIRE ICT
 
5. IO virtualization
Hwanju Kim
 
Scalable Service-Oriented Middleware over IP
Dai Yang
 
Network Stack in Userspace (NUSE)
Hajime Tazaki
 
Grid middleware is easy to install, configure, secure, debug and manage acros...
Paul Brebner
 
Ad

Next generation (ng) firewalls

  • 1. Next Generation (NG) Firewalls • Firewall history • But what about??? • Complexity creep • NG firewalls
  • 2. Firewall history • Routers • Access control lists (non-stateful) • Firewalls • Stateful firewalls appeared mid 90s • Fairly simple databases (state tables) • NAT/PAT complicates things (state tables + src & dst ports) • Work at Layer 4 in the OSI 7 layer model 3. Network (IP/ICMP) 4. Transport (host-to-host flow control TCP/UDP) • From wikipedia (sorry!): “Early attempts at producing firewalls operated at the Application Layer, which is the very top of the seven-layer OSI model. This method required exorbitant amounts of computing power and is rarely used in modern implementations.”
  • 3. But what about??? • AKA functionality creep • Intrusion Detection/Prevention Systems • Virtual Private Networks (S2S, C2S) • Application control • Web Proxy • Anti-virus/malware • Identity awareness
  • 4. Complexity creep • All separate devices – creates problems… • Network throughput • Resilience • Cost (Capital and Revenue) • Complexity • Troubleshooting • Down-time
  • 5. NG Firewalls • Massively powerful switch/routers • Massively powerful analysis engines • Architected to analyse multiple of 10Gigabits of traffic in real- time • The type of access-list is entirely different • Instead of: • [IP Address A] can access [IP Address B] on [Port Y] • We can write: • [Users] in the [Finance Group] can access [Finance systems] during [08.00 until 18.00] • [All Students] on [IT Suite PCs] can only access [Social networking sites] between [17.00 and 09.00] • [Anyone] using [bittorrent] can only [upload] at [50kpbs] • [Anyone] using [www] (if not previously known) must [authenticate]