Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Firewall Migrations: Five Ways To Maximise Security Resilience & Availability
Articles

Firewall Migrations: Five Ways To Maximise Security Resilience & Availability

ISBuzz TeamBy ISBuzz TeamJune 9, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Jeff Harris, vice president, solutions marketing at Ixia explores best practices for establishing a security architecture that is both robust and delivers high availability.

If you are planning an upgrade or migration to next-generation firewalls (NGFWs), it is not just an opportunity to gain richer functionality and a wider range of protections.  It is also an excellent time to review your entire security architecture; to ensure it maximizes the value and efficiency of all your security devices, while minimising the risk of network downtime.  This latter point is particularly compelling, as analyst firm Gartner states that the average cost of downtime across a range of industry sectors is well over $300,000 per hour – supporting Benjamin Franklin’s proverb that ‘an ounce of prevention is worth a pound of cure.’

But what does the right architecture look like, and how should you go about building it into your network?  By following the five best practice techniques outlined here, you can ensure that your security architecture maximizes your company’s overall security posture and its efficiency.

1:  Reduce risks of downtime

Reducing the risk of downtime begins with examining your overall architecture and identifying the potential points for failure or performance issues.  The crucial structural feature to avoid is serial inline deployment, in which traffic is passed from one security appliance to the other.  Here, a failure in any single device can stop traffic flow and cause a network outage – which in turn leads to substantial drops in productivity, revenue and even business reputation.

The simple alternative is to use modular bypass switches in front of firewalls and other security appliances.  These switches must continually monitor all inline devices, ensuring that they are ready to receive traffic.  If a device goes down, the bypass switch should steer traffic around it until it is back online.

One potential problem with this approach, however, is that it creates a trade-off between security and network uptime – bypassed traffic may not be inspected with normal levels of rigor while a device is down.  This in turn leads to the second best practice.

2:  An efficient load balancing act

Pairing the bypass switch with a network packet broker (NPB) introduces the added ability to see and inspect inside network packets, and route them only to the appliances that are appropriate for that type of traffic.  This might mean, for example, routing non HTTP/HTTPS traffic around a web application firewall, as there is no benefit from it passing through.

This intelligence-based traffic balancing reduces the unnecessary processing burden on individual appliances – this makes them less likely to become overwhelmed and fail. Once again, network efficiency and security strength is maximized – with the added peace of mind from knowing that all traffic is being inspected by the most relevant tools.

3:  Clever configuration for high availability

With modular bypass switches and NPBs in place, the next step is to configure them for optimum availability.  Many NPBs, for example, are capable of being deployed in what is called Active-Active mode.  This provides automatic and instantaneous recovery of any device in the security architecture while also using available security devices.  Clever configuration is about delivering high availability during normal operations, while fully protecting traffic if and when a device does go down. Done right, users would detect no downtime, and security monitoring is unaffected.

4:  Better visibility with NPBs

It is important not to assume that increasing the number of security devices in your architecture automatically minimizes risk.  The larger and more complex your network gets, the greater the probability of network blind spots. Visibility is as crucial a principle.  An advantage of NPBs is that they provide a comprehensive view of your network environment.  They capture and aggregate traffic, eliminate data duplication, and strip away unnecessary detail.  They can even pre-filter known bad traffic, based on either the originating address or geographic location, allowing you to make intelligent decisions about what traffic to block from reaching your network in the first place.

Out-of-band monitoring tools are best-suited for analyzing network performance, identifying trends and responding to compliance requests. That is, they support the comprehensive and intelligent network visibility that is vital in today’s enterprises. The best tools can be managed remotely and produce customized reports for compliance purposes, supporting the state of continuous compliance that is increasingly demanded.

5:  Future-proofing your architecture

In a world in which dynamic agility is king and social media can spread frustration related to a company’s downtime faster than ever before, customer experience and application availability are vitally important. Future-proofing your security architecture with high-speed bypass switches and powerful NPBs eliminates network downtime caused by unplanned device failure, deployments, maintenance or upgrades.  You can also maximum uptime for your security infrastructure, reduce the load on security appliances, and therefore extend their useful lifespans, while generating efficient traffic analysis.  In addition, you can support growth in network traffic with minimal new investment. Collectively, these benefits help to protect your business against the need for expensive and disruptive future network adjustments.

Bypass switches and network packet brokers create a network security architecture that simultaneously delivers robust protection and operational efficiency – an architecture that works harder for your company, and is able to heal itself in the event of an outage.  In terms of security, prevention truly is better – and cheaper – than a cure.

[su_box title=”About Jeff Harris” style=”noise” box_color=”#336588″][short_info id=’71133′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Five Ways to Improve Your Security Posture, Fast

October 23, 20244 Mins Read

What is Digital Assurance and Why It’s Crucial in Today’s Business Landscape

October 11, 20243 Mins Read

Strengthening Security Posture Through People-First Engagement

October 4, 20246 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}