Posts

Showing posts with the label Firewalls

UTM Explained: Unified Threat Management for the Security+ Exam

Unified threat management consolidates multiple security functions into a single appliance. The argument is simple: a small organisation cannot staff and operate six separate products, so one device with one interface and one support contract is the practical choice. What is consolidated A UTM typically includes a stateful firewall , intrusion detection and prevention , gateway antivirus and anti-malware , anti-spam filtering, web content filtering by category, VPN termination for site-to-site and remote access, application control , and data loss prevention . Many add bandwidth management and reporting. The unifying idea is one policy engine, one log, one management interface, one licence renewal. The trade-offs The exam expects both sides, not just the sales pitch. In favour: lower cost than separate products; a single interface to learn and operate; correlated logging across functions; one vendor to call; and less rack space, power and cabling. For an organisation with one...

NGFW Explained: Application Awareness and UTM for the Security+ Exam

A next-generation firewall adds application awareness, user identity and integrated threat prevention to traditional firewall capability. The exam tests it as the top of a progression, so it is worth learning the whole ladder. The generations Packet filtering (stateless). Examines each packet against rules on source and destination address, port and protocol. No memory of previous packets. Fast, simple, and cannot tell a legitimate response from an unsolicited packet crafted to look like one. Stateful inspection. Tracks connection state in a table, so return traffic for an established session is permitted automatically. This is the baseline for any real firewall, and it is what makes rule sets manageable. Application layer / proxy firewall. Understands specific protocols and can inspect their content, terminating the connection and inspecting before relaying. Thorough, and historically a performance bottleneck. Next-generation firewall. Stateful inspection plus application ide...