Next Generation Firewalls: When to Upgrade and Why

I see you – confident, even a bit smug. And you’ve earned it, because for the last 5 years, the Next-Generation Firewall (NGFW) you chose has been securing your company’s network and doing it well. It came with new innovations to keep things secure, it doesn’t just do allow-list vs deny-list and looks deeper than port or protocol. Its size has kept up with the traffic load, it gets threat signature updates from the vendor, and your superiors are impressed with the granularity of your policies. You made a good investment and plan on it having a few more years of service in it, you’re not looking at replacements.

Now obviously I would want to talk to you about replacing it, I sell firewalls so wouldn’t be doing my job if I didn’t. But you clicked the link, so you’re at least curious – thanks for that – and as we’ve discussed, your current set up is secure, right?

The thing about technology is that it’s always evolving, and the past 5 years have seen some seriously cool innovations come to light. We are in an era of hybrid work, web-based everything, and cyber threats that are smarter and more evasive than ever. You’ve probably seen phishing emails that look like they were written by your CEO – or ChatGPT. The amount of traffic moving via web-based apps and APIs is massive. Getting a grip on that is a big task, not to mention the ingenuity seen from cyber criminals in how their attacks get round security.

Image of a padlock and a laptop

So, what does a modern firewall need to do that your 5-year-old NGFW might not?

Real-time, Encrypted Traffic Inspection

Cyber criminals’ ingenuity must be matched by your security, it needs to be up to date to properly secure you. Today this means updating the attack signatures your firewalls know at least daily and the ability to test and check all traffic even if it’s encrypted. Users of the network expect it to be fast, nobody wants to wait for that email to load. So, making sure security doesn’t impact your network speed is always important. Palo Alto Networks, for instance, achieves all this by including the security checks in-line as one single pass which means your traffic isn’t held up and isn’t being sent all over before being released.

Zero-Day Threat Detection Using Machine Learning

This single-pass of security includes those zero-day attack checks: if your firewall can learn on the job about what’s malicious or not this will save time and keep you more secure. Machine learning can now be used to spot traffic associated with a cyber-attack and stop it there and then, without knowing the attack signature beforehand. This is all to say the newer generation of firewalls have new innovations that have been designed with the new attack landscape in mind.

Support for Modern Network Needs

The way your company’s network is being used has changed meaning the way your security is configured needs updating. Think Point of Entry (PoE) ports, fibre connectivity, and compatibility with newer OS-level security features. Can your current firewall single out ports as safe or unsafe? How about URLs or specific apps? The public facing surface area of your network is larger than ever, with more data to keep safe, and hybrid work, SaaS, and clouds to secure.

Granular App Control

It’s no longer about blocking an app, but controlling what happens inside it. Need to allow a video conferencing app but want to block file transfers with it? Modern firewall features like App-ID makes this possible.

End-of-Life Happens – Eventually

Even the best firewall has a shelf life. Vendors typically give plenty of notice before a device reaches End-of-Life (EoL), but once that date hits, you may find yourself on your own – no more updates, no support, and a growing security risk. Planning ahead avoids a scramble later.

To wrap up, if your firewall is older than 5-years old, it’s done its job – but it might not be doing the job that today’s networks demand. It’s not just about security anymore; it’s about visibility, speed, adaptability, and staying a step ahead of threats.

You’ve made a good investment, now it’s time to look ahead to the next one. Want to learn more about firewall upgrades or see what’s out there? Get in touch – we’d love to help.

 

Eve is our resident ICT Specialist, providing expert insight into ICT equipment and activities, from network audits to down-selection of equipment.

More Articles

Cyber Security Background with Padlock

Palo Alto Networks’ Prisma SASE 3.0

We live in an era where complex digital transformation and remote working are the norm, offering new opportunities for empowering workers, but also bringing increased challenges in IT management and security to organisations.

Read More »