Security

How to Clean Up a Firewall Rule Base

Over time, firewall rule bases tend to become large and complicated. They often include rules that are either partially or completely unused, expired, or shadowed. The problem gets worse if multiple administrators have been making changes or if your organization has many firewalls.

When the rule base gets big and tangled, it starts to affect firewall performance. It is difficult to maintain, and it can conceal genuine security risks. And standards such as PCI-DSS require clean-up of unused rules and objects.

With some help from our customers, I've put together a list of best practices for cleaning up a firewall (or router) rule base. You can do all of these checks on your own, but if you have a Firewall configuration management product, you can run most of them automatically.

Firewall Management Today and Tomorrow

Firewall vendors currently fall short in terms of firewall management functions and the upcoming trends in firewall management. What features are real game changers when it comes to firewall management, and how far along is the market in the development cycle?

Introduction: A Brief History of Firewall Management

Firewall eulogies are premature. Firewalls have been at the cornerstone of network security for almost 20 years and will probably remain so until a paradigm shift occurs.

The first commercial firewall, SEAL, was introduced in the early 90's and was managed through the vi text editor. The Visas firewall, by Bob Braden, was the first firewall with a GUI. Check Point's Firewall-1 3.0 administration tool demonstrates several important concepts, including a rule base with an object-level abstraction and support of one policy across many firewalls.

That was 1996. It's amazing to see how similar this product is to contemporary firewall administration tools; apparently, very little progress has been made.

By contrast, core firewall capabilities have been significantly extended. Starting off as simple packet filters, they quickly merged with routers to perform NAT and went on to do IPSec VPNs, content and URL filtering, SSL VPNs, antivirus, and antispam. Recently, firewalls have merged with IPS and have started providing true application-level filtering and user access.

Firewall management tools were extended in parallel to provide configuration utilities for these new capabilities, but there was no conceptual breakthrough. Firewall management functions simply followed the firewall evolution.

Fortified Defense

Ascent Consulting Services, a company based in Bengaluru, India, has joined with Fortinet to shore up the security of its data center.

Fortinet was founded in Sunnyvale, California, in 2000. It is a market leader in network-security appliances, especially in unified threat management (UTM). A majority of Fortune Global 100 companies deploy solutions provided by Fortinet. The company’s flagship product, Fortigate, delivers ASIC-accelerated performance and integrates multiple security layers. The specialized FortiASIC processors are purpose-built for content and network processing. The company is one of the industry leaders in IT security systems.

Ascent Consulting prides itself on a stable of products and solutions aimed at providing their clients with cost-effective and high-quality solutions. The company offers a wide range of technology, management, and outsourcing solutions. Its products, like iBuild, iForce, and iAsset, combined with services like payroll, compliance, and temporary staffing, make it a leader in its domain. Companies like Thomson Reuters and Yahoo use Ascent’s services.

In a move to implement a world-class security system in its new data center, Ascent chose Fortigate over solutions provided by Juniper, Nortel, and Cisco, to name just a few.

A Fort Knox Of A Data Centre

If information is power, then it has to be guarded zealously and considering that a data centre thrives on information, it is logical that security protocols will rule paramount in the physical and IT DNA of a data centre. In fact some data centre locations itself are kept secret.

Take a look at the 50000 square foot facility that CyrusOne runs in Austin and you will know what the word foreboding means - 8 feet high security fence, biometric security measures, security cameras that stare at you unblinkingly, ‘caged’ personnel and access even to regular clients via ID cards. Intrusion detection systems, firewall management and monitoring services provide the electronic and technological side. Physically, the data centre is protected by bullet proof glass, barbed wire fencing and reinforced concrete bollards and so on.

Access Control Industry Best Practices

With a wide variety of reader technologies to choose from, it’s important to ensure that the technology selected properly balances risk, cost, and convenience factors. Prox technology is a viable choice, especially for sites where there are existing Prox cards in use, but contactless smart cards represent the next generation Prox technology and offer all of the convenience of Prox along with increased security and additional benefits such as multiple applications, read/write and increased memory. However, when selecting a vendor’s system, be aware that some manufacturers, in an attempt to sell “universal” readers capable of reading almost any contactless smart card, bypasses the security measures of contactless smart cards in order to achieve their goal.

Access Control Industry Best Practices

With a wide variety of reader technologies to choose from, it's important to ensure that the technology selected properly balances risk, cost, and convenience factors. Prox technology is a viable choice, especially for sites where there are existing Prox cards in use, but contactless smart cards represent the next generation Prox technology and offer all of the convenience of Prox along with increased security and additional benefits such as multiple applications, read/write and increased memory.

Take the Cobbled Path

San Francisco has been home to Arch Rock for 4 years. The company is a pioneer in IP-based wireless sensor network technology. So far, the company has been concentrating on energy use in commercial and small buildings. Their Energy Optimizer System has been deployed by around twelve customers since it was first introduced in the market in 2009 middle. This System uses wireless sensors which monitor and record the consumption of energy in buildings.

Physical Security of a Data Center and the Budget

Physical security is very important in data center design. The big question that needs to be answered is how much of the budget should be allotted for data center security. The answer to this question is not simple, straight forward and one that would hold true in all situations. What percentage of the budget is to be allotted for physical security of the data center would be determined by multiple factors? Every case has to be dealt with its on merits and constraints.

Security Pros show off new data center monitoring site and security systems

Who better to understand the security needs of a data center then Wackenhut, a provider of security and security-related solutions in the U.S. This month Wackenhunt will open its new data center and with it launch its state of the art remote security monitoring system. This data center will provide central station alarm monitoring.

DCJ Digital Magazine

 

What drives a Data Center? Want to know more about Cost vs Efficiency in Data Center Design?

 

To find out and to read more great articles in this issue, CLICK HERE!

 


DCJ SpotlightON

SpotlightON series continues!

The Data Center Journal has the pleasure of presenting it's interview with Lior Bilk, CFO of Hoboken University Medical Center.  Lior discusses his thoughts on DC cooling as well as thoughts on design and efficiency.  To read the the entire interview please make sure to open today's newsletter.  Not subscribed to the newsletter?  Scroll down on this page and submit your email address.  It's that easy!!!!!


 

Register Today!

Get the NEW & IMPROVED DCJ Bi-Weekly eNewsletter! Sign up below!


E-mail Address:

Latest Comments

DCJ Jobs

Latest Events

Sun Sep 12 @ 8:00AM - 05:00PM
Data Center Insights Summit
Sun Sep 12 @ 8:00AM - 05:00PM
BICSI Fall Conference and Exhibition
Tue Sep 14 @ 9:00AM - 10:00AM
Cisco Data Center Architecture The Power to Say Yes
Thu Sep 16 @ 8:00AM - 05:00PM
DataCentre Expo
Mon Sep 20 @ 8:00AM - 05:00PM
Data Transfer & Data Breach Notification Briefing
Sun Oct 03 @ 8:00AM - 05:00PM
AFCOM Data Center World
Tue Oct 19 @ 8:00AM - 05:00PM
Grreen Data Centers: NY