Showing posts with label Fortinet Practice Exam. Show all posts
Showing posts with label Fortinet Practice Exam. Show all posts

Tuesday, May 21, 2019

Not all Secure SD-WAN Solutions are Created Equal

The SD-WAN market is experiencing rapid growth, with about 50% of organizations expected to have deployed SD-WAN by the end of 2019. But since it relies on direct internet access, SD-WAN introduces security risk, especially when compared to their previous MPLS connections.  And given the current state of today’s threat landscape, security can no longer be looked at as something one does after the deployment of an SD-WAN. Instead, it needs to be baked into the architecture.

To address this challenge, organizations concerned about the risks of the public internet and bolt-on security are looking for a security-driven networking approach that enables secure SD-WAN out of the box. Fortinet was one of the first vendors to introduce “Secure SD-WAN” (in 2016) to deliver fully integrated, security-driven networking capabilities. Fortinet also delivered the industry’s first SD-WAN ASIC, enabling best-of-breed NGFW in the same offering without comprising performance and scalability.



Security Driven Networking is the Right Approach for Secure SD-WAN


Today, many of the more than 60 vendors that offer SD-WAN claim that their SD-WAN solutions include or support security. However, in reality, few vendors actually offer full stack security and instead offer stateful firewalls which aren’t as effective. Organizations with a healthy concern for risk need to take note. To address that issue, NSS Labs has recently published their NSS Labs SD-WAN Intelligence Brief research paper designed to help organizations understand strengths and limitations of product offerings to ensure that their SD-WAN implementations do not compromise the security or integrity of their organizations or impose undue challenges in terms of deployment or management.

In this paper, NSS Labs explains why having security built into an SD-WAN solution is the right approach for successful WAN Edge deployments. According to NSS Labs, the security provided in a “Secure SD-WAN” solution should align with the capabilities provided in NGFW technology; “In our (NSS Labs’) opinion, secure SD-WAN products from non-firewall vendors currently do not meet all firewall use cases, and should be evaluated carefully.”

The reason this is important is that organizations have come to expect that they will need to add security to any networking solutions or components they deploy. But given the potential networking complexities of SD-WAN, adding security as an afterthought to dozens or more connected branch offices—especially where there may not be any IT staff located in the branch office being connected—can be overwhelming. Which is why even organizations simply reviewing SD-WAN solution to consolidate point products and reduce operational cost should not reduce their expectations for protection.

Fortinet’s Real Secure SD-WAN Solution Continues to Garner Third-Party Validation


In that regard, Fortinet’s Secure SD-WAN solution is experiencing rapid adoption because Fortinet delivers the most comprehensively Secure SD-WAN solution on the market, in addition to its robust suite of advanced routing and WAN optimization functions. NSS Labs has consistently awarded a wide variety of Fortinet solutions their top “recommended” rating for years, including recent NGFW and SD-WAN group test in which Fortinet received a recommended rating. Few other SD-WAN vendors can make the same claim—especially when it comes to bundling advanced networking and security functions together in the same, unified management interface.

One of the reasons why this designation from NSS Labs is important is because the SD-WAN buying center is usually part of the networking/infrastructure team and not the security team, which means that security decisions are often made after the fact rather than insisting on SD-WAN and other networking decisions be security-led.

The NSS Labs report specifically addresses this common misconception by reporting on the importance of not compromising on security to achieve reduced WAN costs with SD-WAN.

Evaluating Your Need for SD-WAN Security


NSS Labs recommends that organizations looking at SD-WAN solutions begin by asking four fundamental security questions:

  1. How will my risk posture change if I adopt SD-WAN technology? 
  2. Can the SD-WAN technology meet our organization’s anti-threat requirements? 
  3. Are there limits to the types of threats that can be detected? 
  4. Is there an operational cost to implementing anti-threat features, and if so, what is it? 

This information can help guide the critical decision of selecting and implementing the sort of SD-WAN solution your organization needs to not only address your digital transformation requirements, but to do so without compromising on security.

The NSS Labs report recommends that organizations exploring SD-WAN deployment through Proof of Concept (PoC) installations plan to include a rigorous testing of security features, evasions, and SSL inspection capabilities. In this way they can best understand best fit for their organization.

Where to Begin


There are many reasons why organizations—especially those somewhat intolerant to risk—should prefer a seamlessly integrated, best-of-breed NGFW security integrated into their SD-WAN. Advanced WAN networking, overlay VPN, and world-class security (NGFW, IPS, Antivirus, Web Security, and even Sandboxing) woven together into a single-pane-of-glass management solution ensures quick low touch/no touch deployment and robust interconnectivity without compromising on critical protection.

To make sure your organization is getting the solution it needs, keep the following in mind:

  1. Secure SD-WAN Proof of Concept (PoCs) projects should include full stack NGFW testing, whether integrated into a solution or deployed later as an overlay solution, for the comprehensiveness of protection and ease of deployment.
  2. With business traffic—especially across public networks—increasingly encrypted, enterprises must evaluate the performance of inspecting SSL and IPSec encrypted traffic so that security does not become a bottleneck for critical and/or latency-sensitive applications and services. 
  3. Review NSS Labs recent SD-WAN and NGFW public test report for a detailed comparison of vendors, in addition to the NSS Labs SD-WAN Intelligence Brief.

Wednesday, April 10, 2019

Fortinet Raises the Bar for Cloud Security

Fortinet has a Longstanding Commitment to Cloud Security Leadership


As digital transformation requirements drive organizations to adopt and expand cloud usage, Fortinet is positioned to support a wide range of cloud migration initiatives—from extending and migrating applications and datecenters to the cloud, to helping companies build applications on the cloud through helping customers consume SaaS applications.

Due to the breadth of security offerings (FortiGate, FortiWeb, FortiSandbox, FortiMail, etc.) available on all six of the leading cloud platforms (Alibaba, AWS, Azure, Google, IBM, and Oracle), Fortinet is uniquely positioned to offer organizations the confidence to deploy any application on any cloud as they can take their security with them supporting any cloud adoption initiative.

Four Major Advances in Cloud Security


In keeping with our Fortinet’s long history of security innovation on premise, Fortinet offers these expertise for the cloud as well. We are proud to announce Four new advances that further demonstrate our commitment to the variety of cloud adoption initiatives organizations are undertaking—enabling them with the confidence needed due to consistent security across their entire infrastructure even as their cloud and networking initiatives continue to evolve.

1. Accelerated Performance—Virtual Security Processor (vSPU) for FortiGate VM


As organizations migrate existing applications into the cloud, they too often find that many of these applications—especially those with high performance requirements—cannot benefit from the flexibility and potential that these new cloud architectures have to offer. Quite often, this is due to the performance constraints inherent in the virtual security solutions they have deployed to protect themselves and their resources, and not in the cloud environment itself. To truly unleash the potential of the cloud’s scale, customers need a new class of high-performance virtual security appliances designed for cloud environments.

Fortinet’s new Virtual Security Processing Unit (vSPU) for the FortiGate-VM solution, modeled after the award-winning security ASICs in place in Fortinet’s physical devices, extends accelerated security performance into private and public clouds. Our new vSPU technology enables customers to migrate their high performance applications to the cloud without compromising on speed or security. It also supports a variety of other use cases, including highly available, large scale VPN in the cloud.

Fortinet’s revolutionary vSPU architecture provides a whole new level of performance for virtual security. We also made the process of integrating with new acceleration technologies much easier, which, in turn, provides customers with the benefit of early access to high performance security in the public and private cloud.

Fortinet has achieved this by applying our 15+ years of proven hardware design leadership to cloud software by optimizing code, eliminating unnecessary processing, and addressing many of the processing challenges and complexities faced by other security solutions. As a result, Fortinet is now the first to market with high performance support for AWS C5n and Intel QAT, on top of their existing support for DPDK and SR-IOV running in a variety of environments.

2. Cloud Security Analytics—FortiCASB-Cloud 4.1


Gartner predicts that through 2023, at least 99% of cloud security failures will be the result of misconfiguration. So whether an organization is migrating to the cloud or building cloud-native applications, the cloud’s management interface is one of the new threat vectors that organizations need to address. In fact, while many organizations are still trying to use their traditional security tools to deal with cloud security issues, it is important to realize that none of these tools  address the threats associated with the misconfiguration of cloud infrastructures—let alone the potential risks associated with such misconfigurations being distributed across multiple disperse and distinct cloud infrastructures.

The cloud security management capabilities provided by FortiCASB-Cloud 4.1 provides organizations with the visibility and controls they need to mitigate the growing risks associated with the configuration of their public cloud infrastructures, as well as with the applications they have built in the cloud.

FortiCASB-Cloud powers security teams with insights and information that help them communicate cloud security information and findings more effectively with cloud DevOps teams. This information helps them better address potential risks, such as those that can be addressed through modifications to infrastructure code in the CI/CD pipeline. Among its capabilities. FortiCASB-Cloud offers organizations the ability to investigate security events, optimize security configurations, and assess an overall security posture against internal or external policies and regulatory requirements.

FortiCASB-Cloud leverages the public cloud management API to monitor activity and configure multiple public cloud resources on AWS, Azure, and Google Cloud Platform
FortiCASB-Cloud continuously evaluates configurations across regions and public cloud types to:
                - Provide guidance on security best practices
                - Offer threat and risk management tools to help mitigate cloud risk
                - Trace misconfigurations to their source
                - Enable regulatory compliance violation reporting

3. Container Security


As organizations build native cloud applications. they often leverage emerging technologies such as containers and serverless workloads. The use of these technologies to accelerate the application development process is accelerating digital transformation. However, traditional security tools—even those designed for the cloud—cannot address all of the security needs of these workloads.

FortiGate (FortiOS 6.2) Fabric Connectors and New Technology Partners


Fortinet offers a comprehensive Container and emerging technology solution for our customers through a mix of organic products and tools, and integrations with 3rd parties. 


FortiOS 6.2 addresses these cloud container challenges with the following advances:

  • FortiGate running FortiOS 6.2 Fabric Connectors delivers container-aware security by helping customers secure any traffic entering or leaving (north-south) their container clusters using logical policies based on labels and meta-data information attached to container resources. Since containers cannot be defined using static IP address information, these capabilities are essential when securing container-based workloads for publicly facing cloud applications.
  • FortiCASB-Cloud 4.1 delivers container-aware security by providing full visibility into container service configuration risk profiles and vulnerabilities, as well as well as detailed traffic analysis to and from container hosts.
  • Fortinet Cloud Technology Alliance Partnerships deliver container-integrated security with partnership with companies like: (1) Tufin, through their cloud-native Iris platform that manages native cloud security ,as well as their Orca platform that manages Kubernetes security without agents, and (2) Alcide, which offers deep integration into serverless and container-based workloads, leveraging emerging standards such as Istio, and supporting agents for containers. 


4. FortiMail 6.2 O365 Connector


For those organizations that consume O365 applications, many find it hard to implement a network-heavy security product which requires potentially challenging changes to network configuration. Fortinet addresses this challenge by offering organizations the ability to easily attach an industry-leading mail security to their O365 Exchange online instances that has been optimized for cloud performance and that functions as a cloud-native solution.