{"id":56370,"date":"2018-01-09T05:00:23","date_gmt":"2018-01-09T13:00:23","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=56370"},"modified":"2019-01-29T12:55:34","modified_gmt":"2019-01-29T20:55:34","slug":"5-critical-mistakes-avoid-incorrectly-sizing-future-ngfw","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2018\/01\/5-critical-mistakes-avoid-incorrectly-sizing-future-ngfw\/","title":{"rendered":"5 Critical Mistakes to Avoid: Incorrectly Sizing Your Future NGFW"},"content":{"rendered":"<p><em>This post is part of a <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/tag\/5-critical-mistakes\/\">blog series where we dive into the five critical mistakes<\/a> to avoid when evaluating a next-generation firewall. Avoid these, and you\u2019ll be well on your way to picking the right next-generation firewall.<\/em><\/p>\n<p>How will you know if the NGFW you\u2019re considering is the right one for your organization? The safest bet is to test it. But when evaluating and selecting a new NGFW, there are some common mistakes security professionals often make. One of these critical mistakes is highlighted in detail below, along with insight and recommendations to help you avoid the blunder.<\/p>\n<p><strong><br \/>\nMistake #1: Incorrectly Sizing Your Future NGFW<\/strong><\/p>\n<p>Avoid relying solely on datasheets and other \u201cperformance on paper\u201d summaries as they are inaccurate points of comparison for firewalls. There are fundamental differences in features and offerings from one firewall vendor to the next. For example, one vendor might measure consolidated threat prevention features (e.g., intrusion prevention systems, antivirus, command and control, URL filtering) in terms of performance impact, while another might highlight performance impact based solely on best-of-breed IPS capabilities in a stand-alone box. To ensure accurate \u201capples to apples\u201d firewall comparisons, organizations should size capabilities to their real-world environments\u2019 requirements (e.g., IPS, application control, advanced malware detection), in addition to the traffic mix. When doing so, it\u2019s critical to account for performance impact resulting from enabling other features in the future.<\/p>\n<p>In addition, advanced capabilities, such as SSL decryption, will vary in performance impact depending on processing logistics. Some vendors decrypt using the hardware form factor, while others decrypt using software \u2013 each with varying degrees of performance effect. Further, threat response performance should only be compared with all required signatures activated. Carefully read the documentation for out-of-the-box collections of signatures to determine actual coverage. Performance often continues to degrade with the introduction of additional signatures.<\/p>\n<ul>\n<li><strong>Avoid trade-offs between security and performance.<\/strong> You should never have to decide between enabling a feature or signature and crippling your performance.<\/li>\n<li><strong>Accurately map to your requirements for throughput and traffic composition.<\/strong> It is difficult to argue against testing the actual traffic to be secured. Simulators can\u2019t represent custom applications, real-world usage scenarios or shadow IT.<\/li>\n<\/ul>\n<p>To correctly size your next NGFW while also ensuring maximum performance, security and ROI, run a proof of concept in your organization. A POC allows you to accurately test next-generation firewalls, their affiliated services and subscriptions \u2013 either on their own or against one another \u2013 in your actual, operational IT environment, whether it is physical, virtual or a hybrid.<\/p>\n<p>For more critical mistakes to avoid when evaluating a next-generation firewall, download the white paper: <a href=\"http:\/\/go.paloaltonetworks.com\/5mistakes\">5 Critical Mistakes When Evaluating a Next-Generation Firewall<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We dive into the first of five critical mistakes people make when choosing a next-generation firewall. <\/p>\n","protected":false},"author":249,"featured_media":56373,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[5,6717],"tags":[5190,145,111],"coauthors":[2745,1419],"class_list":["post-56370","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-firewall","category-products-and-services","tag-5-critical-mistakes","tag-next-generation-firewall","tag-ngfw"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2018\/01\/shark-520x320_LinkedIn.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/56370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/249"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=56370"}],"version-history":[{"count":4,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/56370\/revisions"}],"predecessor-version":[{"id":61576,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/56370\/revisions\/61576"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/56373"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=56370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=56370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=56370"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=56370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}