Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
FBI warns of holiday cyber scams
U.S. Open used Web filtering to prevent online gambling
Google Earth used by terrorists in India attacks
Mumbai terrorist attacks don't deter technology companies
Google layoffs: 10,000 jobs being cut, report claims
Experts to Feds: Sign the DNS root ASAP
Cisco shutting down between holidays
Sprint completes Clearwire WiMAX deal
Mobile sales to beat economic gloom, forecasts Ovum
Start-ups starting to feel economic pain
Spam levels fluctuate as crooks try to revive botnets
Mozilla eyes extra beta for Firefox 3.1
Grim forecast for holiday e-commerce sales
Talking Web, memory assistants and solar-powered cell phones headed mainstream, IBM says
Massive botnet returns from the dead, starts spamming
SMB Networks / Security /

Firewall program aims to protect remote offices

Related linksToday's breaking news
Send to a friendFeedback
Telework Beat archive

The firewall market is a pretty wild and wooly place. You've got hardware and software products targeting big companies and small, being built into routers and gateways, and gunning for consumers' desktops. Just as confusing is the variety of technologies in play. Do you want a proxy firewall; a network address translation firewall; one that employs stateful packet inspection?

Until now, the International Computer Security Association Labs (ICSA) firewall certification program has used a one-size-fits-all set of criteria to test the security of firewall devices. As a result, some lower-end products have gone uncertified, leaving small-office workers and consumers to scratch their heads over technical jargon, weigh marketing hype and worry whether their networks are suitably protected.

Advertisement:

The good news is ICSA Labs is about to unveil Version 4.0 of the certification program, which addresses the changing market. A two-step process, 4.0 certification requires a product to pass a baseline set of criteria, and be tested against its target audience and the characteristics of the networks involved. Vendors must be tested in the residential/consumer, small office/branch office/teleworker, or traditional corporate categories.

In the residential/consumer environment, the idea is "to protect users who don't know what a firewall is but think it's a good idea to have one," says Al Potter, manager of ICSA's network security lab. To pass the test, the firewall device must be easy to configure, and safe by default. It needn't support inbound services or include remote management features.

In the second category, the firewall device sits in the home office or branch office and is managed remotely by an IT administrator in the corporate office. Such a device must be connected and administered from the public side of the firewall through an encrypted channel, and should allow for some inbound services to an e-mail and Web server. The third category is a traditional corporate firewall, the criteria of which remains relatively unchanged.

"We shaped these categories to reflect the way they're being used," Potter says. "We each asked ourselves: How do I configure my firewall? The answer is, I allow everything out but nothing back in. That's fine at home but not for the enterprise."

Other activity at ICSA Labs includes the development of a new host-based firewall program for certifying desktop firewalls. This too will include separate modules targeting the corporate market and consumer markets.

Potter says the Labs will turn its attention later down the road to developing a module for measuring firewall performance. "Four or five years ago, the focus was on security, then on features. Now that these are a given, performance will become the primary interest," adds firewall programs manager Brian Monkman.

RELATED LINKS

Toni Kistner is managing editor of Net.Worker. Contact her at tkistner@nww.com.

Telework Beat archive
Past columns.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.