Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Security overlay architecture holds promise

IPolicy innovates in enterprise security space
Wide Area Networking Alert By Steve Taylor and Joanie Wexler , Network World , 05/06/2004
Steve Taylor
Sign up for this newsletter now!

WAN experts Steve Taylor and Jim Metzler analyze and share best practices on WAN issues from optimization to management.

We often laud the innovation we see in quality-of-service appliances that enforce application-prioritization rules by inspecting packets through Layer 7. These appliances, from companies such as Allot and Packeteer, deliver some intrusion detection and denial-of-service protection side benefits, thanks to their ability to identify traffic and shape it according to policy.

Now enter iPolicy Networks, with WAN-edge gear that works in a conceptually similar manner but sets and enforces security policies, rather than QoS policies, as its primary function.  The company's IP Enforcer product line tackles the many facets of enterprise network security in a single, overlay architecture with a unified management system, which the company announced this week.

Given that enterprises are fretting over their network security infrastructures (see "User group defines security needs," http://www.nwfusion.com/news/2004/0426nac.html), the idea of a do-it-all network security overlay that leaves your routing/switching infrastructure intact sounds pretty appealing. What remains to be seen, of course, is how iPolicy gear fares amidst the old reliables in the network security space, such as CheckPoint, Cisco and NetScreen.

Among the security tasks that iPolicy's IP Enforcer equipment and Unified Security Manager software reportedly support:

* Firewall filtering (access control).
* Content (URL and spam) filtering.
* Intrusion detection and prevention (applied to traffic and protocol anomalies).
* VPN encryption.
* Anti-virus protection and automatic updating.
* Correlation of multiple risks in a single event.

IPolicy has created a new industry product category for its Layer 3 - 7 security devices: "intrusion prevention firewalls." Because all the security applications are integrated - a device can inspect a given packet just once against multiple rules - the company says it does not take the performance hit that some competing products do when running multiple security applications.

Those products combine multiple functions into a single device, but within the device, each function must inspect each packet separately, says Manish Gupta, director of marketing at iPolicy. Many also require separate management systems to set rules against each security function, he says.

These seem like valid issues you might wish to check out with potential vendors when evaluating products.

Next time: More on the architecture specifics, pricing, and other security issues and alternatives.

Partner Content

Simplify Your Branch Infrastructure

Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.

Download the Free Info Kit

Next-Gen Load Balancing

Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.

Download the Free Guide

Accelerate Your Web Apps by up to 5x

Free Guide: "The Secret to Getting Maximum Speed from your Web Applications." Learn how you can deliver Web apps up to 5x faster.

Download the Free Guide

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Whitepapers

Advancing the Economics of Networking

Aging network systems and old habits have dictated how businesses spend their IT budgets. As a...

Implementing HA at the Enterprise Data Center Edge to Connect to a Large Number of Branch Offices

This paper reviews the problem of creating a network where the dynamic availability of services is...

Enterprise Data Center Network Reference Architecture

Using a High Performance Network Backbone to Meet the Requirements of the Modern Enterprise Data...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

How to cut IT costs with wide-area data services (WDS)

Discover how you can realize dramatic cost savings with Wide-area Data Services in this new webcast...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

Ethernet Services: WAN options mature

WAN Ethernet services are reliable, cost-efficient offerings that are widely available and in a...

Keeping Spam at Bay

The editors of Network World bring you this informative compilation of news, trends, analysis,...

Get More From Your WAN

Download this Network World Executive Guide and get information that details how real-world...