Questions tagged [ngfw]

Term which is used today to describe almost every general purpose firewall appliance which can do some kind of application layer filtering.

The term NGFW (Next Generation Firewall) was originally coined by Palo Alto Networks to marked their system differently from simple packet filters which work only on layer 3/4, application layer gateways (secure mail gateway, secure web gateway,...) and also IDS/IPS (intrusion detection/prevention systems). While the original term naturally matched perfectly only systems by Palo Alto Networks it was quickly adopted by other companies and often replaced the previous IDS/IPS or Secure Gateway marketing. This means it is today used to describe a variety of devices with different capabilities but which all can do some kind of application level filtering.

4 questions
4
votes
1 answer

How SSH Deep Inspection works?

I just saw an option in Fortinet NGFW regarding, SSH Deep Inspection. So my question is how Deep inspection or whatever can inspect or find any malicious activity on encrypted packets?
arif
  • 1,088
  • 13
  • 24
2
votes
3 answers

How does a NG Firewall do application visibility and classification of TLS traffic without TLS interception and how reliable is this

How Does Application Visibility and Control Work? The application identification (App ID) classification engine and application signature pattern-matching engine operate at Layer 7 and inspect the actual content of the payload for…
emirjonb
  • 121
  • 5
1
vote
2 answers

The security of IP whitelisting large ranges

I am not a network expert but; a recent conversation has come up with a client asking to whitelist a range of ip's (let's say 250 odd for now) to transfer their data to us for processing. I should add here that we would provide an IP address to the…
0
votes
1 answer

micro segmentation in the campus

We have so many devices (IoT and wintel, macs, androids, ios) spread across a few VLANs. Worried about any one device getting affected (e.g. Ransomware) and potentially infecting all other devices on the VLAN. Do you see this as a problem too? Any…
Ricky
  • 3
  • 3