#radio Radio Serbia by EnjoyIT 1.0 http://t.co/nGQFvX2E
9 minutes ago by RealTonyRocha on twitterZDNet is available in the following editions:
Legacy enterprise firewalls which rely on port and protocols are becoming irrelevant in Web 2.0 landscape as these systems can be easily bypassed, says firewall expert.
palo alto, larry link, internet connectivity, internet, science and technology, computer security, computer technology, technology, internet protocols, software
Web 2.0 applications are rendering first-generation enterprise firewalls "useless" as users are able to bypass these legacy technologies easily, said a Palo Alto Networks executive.
In an interview with ZDNet Asia Wednesday, Mao Yuming, chief architecture and co-founder of Palo Alto Networks, said legacy firewalls that rely on port and protocols to define traffic are not effective in the Web 2.0 landscape.
One of the ways applications can bypass firewalls is by using HTTP (Hypertext Transfer Protocol) or HTTPS (Hypertext Transfer Protocol Secure) as launch points, he said.
Therefore, firewalls should identify data not at port or protocol level but at the application level, Mao said, adding that Palo Alto Networks' "next-generation firewalls" features three core identification technologies catered to today's applications landscape.
One such technology is App-ID, which lets organizations manage the applications that are allowed in their networks. On top of that, to better advise its customers, Palo Alto has a dedicated team that daily tracks and updates into its database apps and new app variations.
Larry Link, the company's vice president of worldwide sales, added that Palo Alto's customers also submit their list of applications to the global list. The company also works with universities, where "a lot of applications are first seen"--equipment is in place to track application traffic and identify newly-created applications, he explained.
User-ID, another feature, defines users' access policies based on user identity instead of the traditional way of tracking IP addresses.
"IP address is not relevant anymore, especially when more and more users are using notebooks," Mao said, pointing out that users' IP address changes when they work at different locations within the corporate environment.
With User-ID identification technology, Palo Alto leverages the organization's directory service and converts it into a user identity so that even when the user's IP address changes, the same access policy is applied to the user, he said.
Another technology included in Palo Alto's hardware-based firewalls is Content-ID, which is able to process data, threats and URLs in a single scan so there is no latency, Mao added. This contrasts with other commercially available firewalls where "firewall helpers" such as IPS (intrusion prevention systems) and antivirus are added in the form of additional boxes, which slow down their capabilities.
While behind-the-scene firewalls are important, Mao said it is equally important for IT administrators to be able to see the ongoing network activities. Palo Alto's products include the Application Command Center which graphically displays network activities such as the applications on the network, users using a particular application and the potential security impact of the application.
Firewall's role in mobile workforce
Asked how the proliferation of smartphones in the workforce has affected firewall deployment, Link noted that security related to accessing the corporate network through mobile phones is rated as a low priority among its customers.
Instead, organizations are more concerned about enforcing firewall policies on company-owned laptops, he said. This is especially the case with mobile workforces, which often access the Internet from external gateways and have the potential to introduce threats back into the corporate network.
To help address that concern, the company recently announced a new product called Global Protect, which aims to provide the same level of control to mobile devices, said Link.
The software, installed on laptops, will have preliminary security functions such as checking the status of the machine to ensure that security measures are in place. The tool, he explained, also prohibits the device from connecting to the Internet without going through Palo Alto gateway. It would search for the nearest gateway to connect out to the Internet, so that traffic is redirected through the gateway.
The next step for the company, added Link, will be to develop a similar tool for mobile devices.
Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR
39 minutes ago by GeorgeHAllenGA on twitterRise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c
39 minutes ago by MergeAcquire on twitterRT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb
54 minutes ago by 666hellscream on twitterCFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX
1 hour ago by HarishAitharaju on twitterRise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o
1 hour ago by zdnetasia on twitterRT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o
1 hour ago by wrikent3500 on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoidRise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL
1 hour ago by MandAWorldwide on twitterRise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir
1 hour ago by V_RaV on twitterhttp://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt
1 hour ago by RavtachSolution on twitterRise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in
1 hour ago by EllyZDNetAsia on twitterAlibaba seeks $2.3B from shareholders for Yahoo deal. http://t.co/qLRAhRQk
1 hour ago by zdnetasia on twitterCFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb
1 hour ago by zdnetasia on twitterOfficial UEFA #EURO2012 app with Orange 2.0 http://t.co/yoAOXTI1 #hotpeopleifollow
1 hour ago by JohnReporter on twitterI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
3 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
4 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.