中文字幕av专区_日韩电影在线播放_精品国产精品久久一区免费式_av在线免费观看网站

溫馨提示×

溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊×
其他方式登錄
點擊 登錄注冊 即表示同意《億速云用戶服務條款》

2019度網絡防火墻的魔力象限報告

發布時間:2020-06-14 06:52:05 來源:網絡 閱讀:4059 作者:YIBOWAY 欄目:安全技術

Magic Quadrant for Network Firewalls
用于網絡防火墻的魔力象限
Published 17 September 2019 - ID G00375686 - 86 min read


With firewall providers embedding multiple security features in firewalls and enabling integration and automation capabilities with other security products, firewalls are evolving into network security platforms.
隨著防火墻提供商在防火墻中嵌入多種安全特性,并支持與其他安全產品的集成和自動化功能,防火墻正在演變為網絡安全平臺。
? Strategic Planning Assumptions
? 戰略規劃目標

By 2024, 20% of new distributed branch office firewall deployments will switch to firewall as a service, up from less than 5% today.
到2024年,20%的新的分布式分支機構防火墻部署將以服務的形式切換到防火墻,而目前這一比例不到5%。
By 2024, 25% of new firewall deployments will have users consider cloud-native firewall policy support of infrastructure as a service (IaaS) platforms as a mandatory selection criterion, from less than 5% today.
到2024年,25%的新防火墻部署將要求用戶將基礎設施即服務(IaaS)平臺的云本地防火墻策略支持作為強制選擇標準,而目前這一比例還不到5%。
By year-end 2024, 25% of firewall end-user spend will be contained within larger security “platform” deals delivered by enterprise license agreements (ELAs), up from less than 5% today.
到2024年年底,由企業許可協議(ELAs)提供的更大的安全“平臺”交易將占到防火墻終端用戶支出的25%,而目前這一比例還不到5%。
By 2024, 50% of new firewall purchases in distributed enterprises will utilize SD-WAN features with growing adoption of cloud-based services, up from less than 20% today.
到2024年,在分布式企業中購買的新防火墻中,有50%將使用基于云服務的SD-WAN特性,而目前這一比例還不到20%。
Market Definition/Description市場定義/描述
This year, Gartner has modified the definition of network firewalls. As we are observing more clients moving toward hybrid networks and seeking firewall capabilities in the cloud, cloud vendors are also offering native firewall capabilities to their clients.
今年,Gartner修改了網絡防火墻的定義。隨著我們觀察到越來越多的客戶端轉向混合網絡,并在云中尋找防火墻功能,云供應商也在為他們的客戶端提供本地防火墻功能。
The traditional firewalls also offer support for these cloud platforms. Hence, starting this year, Gartner has started to also evaluate the native firewall capabilities of cloud providers, along with stand-alone firewall vendors. Also this year, the Magic Quadrants for Enterprise Firewalls and Unified Threat Management (UTM) have been consolidated into a single Magic Quadrant for Network Firewalls.
傳統的防火墻還提供對這些云平臺的支持。因此,從今年開始,Gartner也開始評估云提供商的本地防火墻功能,以及獨立的防火墻供應商。同樣在今年,用于企業防火墻和統一威脅管理(UTM)的魔力象限也被合并到用于網絡防火墻的單個魔力象限中。
Gartner defines the network firewall market as follows: The network firewall market represented by this Magic Quadrant is composed primarily of firewalls offering bidirectional controls (both egress and ingress) for securing networks.
Gartner對網絡防火墻市場的定義如下:這個魔力象限所代表的網絡防火墻市場主要由提供雙向控制(出口和入口)以保護網絡的防火墻組成。
These networks can be on-premises, hybrid (on-premises and cloud), public cloud or private cloud. Network firewalls can also offer additional capabilities such as application awareness and control, intrusion detection and prevention, advanced malware detection, logging, and reporting.
這些網絡可以是主集群、混合型(主集群和cloud)、公有云或私有云。網絡防火墻還可以提供其他功能,如應用程序感知和控制、***檢測和預防、高級惡意軟件檢測、日志記錄和報告。
The companies that serve this market have an identifiable focus on network-based firewall controls — as demonstrated by the proportion of their sales and delivered with their support, sales teams and channels. These vendors provide features dedicated to solve firewall requirements and serve firewall-related use cases.
服務于這一市場的公司有一個明確的重點,即基于網絡的防火墻控制——這可以從他們的銷售比例和他們的支持、銷售團隊和渠道中得到證明。這些供應商提供專門用于解決防火墻需求的特性,并提供與防火墻相關的用例。
This Magic Quadrant includes the following types of network firewalls:
這個神奇的象限包括以下類型的網絡防火墻:
? Purpose-built physical appliances專用的物理設備
? Virtual appliances虛擬設備
?
? An embedded firewall module嵌入式防火墻模塊
? Firewall controls delivered from IaaS platform providersIaaS平臺提供商提供的防火墻控制
Magic Quadrant
Figure 1. Magic Quadrant for Network Firewalls
Source: Gartner (September 2019)

2019度網絡防火墻的魔力象限報告
Vendor Strengths and Cautions
供應商的優勢和注意事項
Barracuda
Barracuda is based in Campbell, California. Its firewalls are visible on public IaaS platforms and in SD-WAN-related use cases on Gartner clients’ shortlists.
梭子魚建立在加利福尼亞州的坎貝爾。它的防火墻可以在公共IaaS平臺和Gartner客戶的入圍名單上與sd - wan相關的用例中看到。
These days, with a growing number of firewall vendors offering support for public cloud, Barracuda is facing strong competition because of limited visibility in the on-premises firewall use case. The vendor continues to introduce enhancements related to support for public IaaS platforms and SD-WAN. It is primarily shortlisted by midsize enterprises.
這些天來,隨著越來越多的防火墻供應商提供對公共云的支持,Barracuda面臨著激烈的競爭,因為在本地防火墻用例中可見性有限。供應商繼續介紹與支持公共IaaS平臺和SD-WAN相關的增強功能。它主要是由中型企業入圍的。
Barracuda targets organizations looking for cost-effective security solutions. Its firewall product line (CloudGen Firewall F-Series) includes physical and virtual appliances. It is available on the popular public IaaS platforms Amazon Web Services (AWS), Microsoft Azure and Google Cloud.
Barracuda的目標是尋找經濟有效的安全解決方案的組織。其防火墻產品線(CloudGen防火墻f系列)包括物理和虛擬設備。它可以在流行的公共IaaS平臺Amazon Web Services (AWS)、Microsoft Azure和谷歌云上使用。
Its firewall centralized management solution, Control Center, is only available as either a software appliance or a public cloud image. Its security portfolio extends beyond firewalls to web application firewalls, data protection and email security solutions.
它的防火墻集中管理解決方案Control Center只能作為軟件設備或公共云映像使用。其安全投資組合已從防火墻擴展到web應用程序防火墻、數據保護和電子郵件安全解決方案。
Recent product updates include integration with macmon for network access control (NAC) and full integration, and support for Microsoft Azure Virtual WAN, as well as new firewall instances in Microsoft Azure, Google Cloud Platform and AWS. Barracuda also discontinued its hardware appliances for centralized management, focusing on virtual and IaaS deployments.
最近的產品更新包括與macmon網絡訪問控制(NAC)的集成和完全集成,以及對Microsoft Azure虛擬WAN的支持,以及Microsoft Azure、谷歌云平臺和AWS中的新的防火墻實例。Barracuda也停止了硬件設備的集中管理,專注于虛擬和IaaS部署。
Strengths優勢 SD- WAN軟件定義廣域網:是將SDN技術應用到廣域網場景中所形成的一種服務,這種服務用于連接廣闊地理范圍的企業網絡、數據中心、互聯網應用及云服務。
? SD-WAN: Barracuda offers mature SD-WAN capabilities within its firewalls. It has extended this SD-WAN support, including tunnels between Barracuda devices and support of the new Microsoft Azure Virtual WAN.
? SD-WAN: Barracuda在其防火墻內提供成熟的SD-WAN功能。它擴展了對SD-WAN的支持,包括Barracuda設備之間的
隧道和對新的Microsoft Azure虛擬WAN的支持。
? Product: Barracuda continues to enhance support for public IaaS platforms. It offers easy-to-use templates for connecting on-premises environments to multiple public IaaS vendors, specifically AWS, Microsoft Azure and Google Cloud Platform for creating policies and rules. Cloud connections to all cloud providers are configured and monitored from the centralized management console.
? 產品:梭子魚繼續加強對公共IaaS平臺的支持。它提供了易于使用的模板,用于將本地環境連接到多個公共IaaS供應商,特別是AWS、Microsoft Azure和谷歌云平臺,用于創建策略和規則。從集中式管理控制臺配置和監視到所有云提供商的云連接。
? NAC: In addition to offering integration with macmon (an NAC vendor), the vendor offers a lightweight NAC solution called Barracuda Network Access Client combined with its SSL solution for basic client health checks.
? 除了提供與macmon(一個NAC供應商)的集成之外,該供應商還提供了一種輕量級的NAC解決方案,稱為Barracuda Network Access Client,它結合了SSL
解決方案,用于基本的客戶端健康檢查。
? Customer Feedback: Surveyed customers report higher-than-average overall satisfaction, with Barracuda highlighting ease of deployment, centralized management and service.
? 客戶反饋:接受調查的客戶總體滿意度高于平均水平,梭子魚強調部署的便利性、集中管理和服務。
? Product Strategy: The retirement of the small and midsize business (SMB)-oriented X-Series and on-premises management appliance simplifies the overall product line and centralized management options.
? 產品策略:退休的面向中小型企業(SMB)的x系列和本地管理設備簡化了整體產品線和集中管理選項。
Cautions注意事項
? Customer Experience: A lack of a complete set of APIs and missing integration with the Barracuda Content Shield endpoint security solution were cited as key concerns by customers surveyed. However, in the recent firmware release (8.0), the vendor has made enhancements by offering support for relatively more APIs.
? 客戶體驗:缺少一套完整的api,并且缺少與Barracuda Content Shield端點安全解決方案的集成,這些都是被調查的客戶所關注的關鍵問題。然而,在最近的固件版本(8.0)中,供應商通過提供對更多api的支持進行了增強。
? Sales Execution: While the vendor offers firewall appliances scaling from 1.2 Gbps to 46 Gbps (pure stateful inspection throughput), Gartner does not see them as a preferred shortlist for data center and enterprise perimeter use cases by Gartner clients.
? 銷售執行:雖然供應商提供的防火墻設備從1.2 Gbps擴展到46 Gbps(純有狀態檢查吞吐量),但Gartner并不認為它們是Gartner客戶的數據中心和企業邊界用例的首選候選名單。
? Marketing Execution: Resellers express concern that potential customers do not see the vendor as enterprise-grade or competing with larger competitors. Despite receiving high marks for ease of cloud connectivity with CloudGen Firewalls, the overall adoption rate of virtual firewall instances within IaaS as either pay-as-you-go or bring-your-own licenses remains low.
? 營銷執行:經銷商表示,他們擔心潛在客戶不認為該供應商是企業級的或與更大的競爭對手競爭。盡管CloudGen防火墻在云連接方面獲得了很高的分數,但IaaS中虛擬防火墻實例的總體采用率(即使用即付或自帶許可)仍然很低。
? Geographic Strategy: Barracuda remains primarily focused on North America and Europe, and is not often seen in South America, the Asia/Pacific region and the Middle East.
? 地理戰略:梭子魚的市場主要集中在北美和歐洲,在南美、亞太地區和中東并不常見。
? Market Responsiveness: Barracuda lacks a FWaaS offering and any cloud access security broker (CASB) integration, which is a favorable requirement with the growing use of SaaS applications. The firewalls also lack support for SDN platforms.
? 市場響應性:Barracuda缺乏FWaaS產品和任何云訪問安全代理(CASB)集成,這是SaaS應用程序使用不斷增長的有利需求。防火墻也缺乏對SDN平臺的支持
? Sandboxing: The vendor lacks an on-premises network sandboxing product, but offers integration with Lastline.
? 沙盒:供應商缺少本地網絡沙箱產品,但提供與Lastline的集成
? Product Certification: Barracuda firewalls lack certain certifications that are important to enterprises with heavy regulations such as Common Criteria EAL4.
? 產品認證:Barracuda防火墻缺乏某些認證,而這些認證對于法規嚴格的企業來說非常重要,比如通用標準EAL4。
Check Point Software Technologies CP軟件技術科技
Check Point Software Technologies is a global pure-play security vendor, with headquarters in Tel Aviv, Israel, and San Carlos, California. Its firewalls are facing strong competition from leading firewall players in the market.
Check Point Software Technologies是一家全球性的純安全性供應商,總部位于以色列的特拉維夫和加州的圣卡洛斯。它的防火墻正面臨來自市場領先防火墻廠商的激烈競爭。
Gartner is gradually noticing the vendor’s decreasing visibility for different firewall use cases in client inquiries as compared to other Leaders. With Check Point now showing a focus on cloud and application security with acquisitions, if executed well, it can gain traction in these use cases.
Gartner逐漸注意到,與其他領導者相比,供應商在客戶詢問中對不同防火墻用例的可見性在下降。Check Point現在將重點放在云和應用程序安全上,如果執行良好,它可以在這些用例中獲得支持。
Check Point’s security portfolio, branded as the Check Point Infinity Architecture, includes enterprise firewall appliances (Security Gateway), virtual appliances available on the major cloud platforms (the CloudGuard brand, which includes CloudGuard IaaS, CloudGuard SaaS, CloudGuard Dome9 and CloudGuard Log.ic).
Check Point的安全組合,被稱為Check Point Infinity架構,包括企業防火墻設備(安全網關),主要云平臺上可用的虛擬設備(CloudGuard品牌,包括CloudGuard IaaS、CloudGuard SaaS、CloudGuard Dome9和CloudGuard Log.ic)。
The SandBlast brand encompasses threat prevention technologies, including network sandboxing appliances, an endpoint security solution (SandBlast Agent) and a mobile security solution (SandBlast Mobile). Check Point’s centralized management suites (Security Management, SmartEvent and Compliance) are available as a physical appliance (Smart-1 security management appliance) or as software, with a Windows-based management console (SmartConsole).
噴沙品牌包含威脅預防技術,包括網絡沙盒設備、端點安全解決方案(噴沙代理)和移動安全解決方案(噴沙移動)。Check Point的集中管理套件(安全管理、SmartEvent和遵從性)可以作為物理設備(Smart-1安全管理設備)或軟件使用,帶有基于windows的管理控制臺(SmartConsole)。
Checkpoint introduced four new Security Gateway appliances in the past year. In addition, it acquired Dome9 for cloud security posture management (CSPM) and ForceNock for web application and API protection (WAAP) security. The vendor offers 23 Security Gateway models — from lower-end options to high-end appliances with 1.6 Tbps throughput.
在過去的一年里,Check Point引入了四個新的安全網關設備。此外,它還收購了Dome9用于云安全態勢管理(CSPM)和ForceNock用于web應用程序和API保護(WAAP)安全。該供應商提供23個安全網關模型——從低端選擇到1.6 Tbps吞吐量的高端設備。
Strengths
? Pricing Strategy: Check Point offers a simple pricing model where appliances come with a choice of three bundles of subscriptions: Next Generation Firewall (firewall, intrusion detection and prevention system [IDPS], application control and URL filtering), Next Generation Threat Prevention (Next Generation Firewall features plus antivirus, anti-spam and anti-bot), and Next Generation Threat Prevention & SandBlast NGTX (NGTP plus sandboxing and content disarm and reconstruction). Check Point also offers the Infinity Total Protection ELA, as well as a-la-carte pricing.
? 定價策略:CP提供了一個簡單的定價模型,電器有選擇訂閱的三個包:下一代防火墻(防火墻、*檢測和預防系統(idps)、應用程序控制和URL過濾),下一代威脅的預防(贏面下一代防火墻功能+防病毒、防垃圾短信和的反傀儡程式),預防和下一代的威脅和沙盒仿真NGTX (NGTP加上沙盒和內容解除和重建)。CP還提供無限總保護ELA,以及a-la-點菜定價。
? Product Execution: Check Point has one of the largest threat research teams among the vendors evaluated in this research. It also offers a third-party threat intelligence feed as an additional option for customers, further increasing the scope of its threat intelligence offering. The vendor’s attach rates for its add-on products are higher than many competitors, which improves its threat intelligence capabilities.
? 產品執行:在本研究中評估的供應商中,Check Point擁有最大的威脅研究團隊之一。它還為客戶提供了一個第三方威脅情報提要作為一個額外的選項,進一步擴大了其威脅情報提供的范圍。該供應商的附加產品的附加率高于許多競爭對手,這提高了其威脅情報能力。
? Partners: Check Point has a historically strong partner ecosystem, with VMware, Silver Peak, Microsoft and Radware being the recent additions. The vendor has also launched a new partner program called Check Point Engage that rewards providers that strengthen relationships with Check Point customers focused on cloud and mobile over hardware purchases.
? 合作伙伴:Check Point有一個強大的合作伙伴生態系統,VMware、Silver Peak、Microsoft和Radware是最近加入的。該公司還推出了一個名為Check Point Engage的新合作項目,獎勵那些加強與Check Point客戶關系的供應商,這些客戶關注的是云計算和移動設備,而不是硬件采購。
? Scalability: Check Point has invested heavily in building specialized offerings to respond to vertical-specific challenges, including ruggedized appliances for critical infrastructure, telecom-specific hyperscale, and protocols such as GTPv1, GTPv2, Diameter, SCTP and SS7. The Maestro Hyperscale Orchestrator appeals to certain verticals like telecommunications and carrier-grade networks that value extremely high throughput capacities.
? 可伸縮性:Check Point在構建專門的產品以應對垂直特定的挑戰方面投入了大量資金,包括用于關鍵基礎設施的加固設備、電信特定的超大規模以及諸如GTPv1、GTPv2、Diameter、SCTP和SS7等協議。Maestro超大規模管弦樂編曲吸引了某些垂直領域,如電信和電信級網絡的價值極高的吞吐量能力。
? Feature: Check Point continues to lead in centralized management offerings, even for very large, complex and highly exposed environments. Its management suite includes several features such as multidomain security management and smart provisioning to specifically serve managed security service providers (MSSPs).
? 特性:即使對于非常大、復雜和高度暴露的環境,Check Point仍然在集中式管理產品中處于領先地位。它的管理套件包括多個特性,如多域安全管理和智能供應,以專門服務于托管安全服務提供商(MSSPs)。
? Product Support: Check Point supports a large number of private, hybrid and public IaaS environments with its CloudGuard IaaS product line, including VMware NSX, Cisco ACI, AWS, Microsoft Azure and Azure Stack, Google Cloud Platform, Oracle Cloud, OpenStack, and Alibaba Cloud. With Dome9, Check Point is showing a growing focus on public IaaS.
? 產品支持:Check Point以其CloudGuard IaaS產品線支持大量的私有、混合和公共IaaS環境,包括VMware NSX、Cisco ACI、AWS、Microsoft Azure和Azure Stack、谷歌云平臺、Oracle云、OpenStack、阿里巴巴云。通過Dome9, Check Point越來越關注公共IaaS。
Cautions
? Marketing Execution: Gartner estimates that, in 2018, Check Point lost market share to its rivals and increasingly is less visible in Gartner client inquiries. Client surveys indicate that the vendor is often left off of shortlists when clients are considering replacement of incumbent firewall vendors.
? 市場執行:Gartner估計,2018年,Check Point的市場份額被競爭對手奪走,在Gartner的客戶咨詢中越來越不顯眼。客戶調查顯示,當客戶考慮替換現有的防火墻供應商時,供應商常常被排除在候選名單之外。
? Market Responsiveness: Check Point is lagging its competition in introducing a full FWaaS offering. The vendor continues to lack the SD-WAN focus found with other firewall vendors.
? 市場反應:Check Point在引入全面的FWaaS方面落后于競爭對手。該供應商仍然缺乏與其他防火墻供應商一樣的SD-WAN焦點。
? Product: Check Point Security Management Portal (SMP; cloud-based management console) is only available for limited firewall models and lacks support for the entire firewall series. Check Point firewalls also lack support for TLS 1.3; the product currently downgrades TLS 1.3 connections to TLS 1.2 when decrypting traffic.
? 產品:Check Point安全管理門戶(SMP;基于云的管理控制臺)只適用于有限的防火墻模型,并且缺乏對整個防火墻系列的支持。Check Point防火墻也缺乏對TLS 1.3的支持;該產品目前降級TLS 1.3連接到TLS 1.2當解密流量
? Customer Feedback: Customers and surveyed resellers perceive performance issues requiring purchase of larger appliances than anticipated, giving lower scores for overall performance, especially when enabling multiple features such as DLP. While Check Point is one of the most shortlisted firewalls for public IaaS platforms, clients cite that the installation and deployment process is not a smooth experience and often requires professional services or help from the support team.
? 客戶反饋:客戶和被調查的分銷商認為性能問題需要購買比預期更大的設備,總體性能得分較低,特別是在啟用DLP等多個功能時。雖然Check Point是入圍公共IaaS平臺的最常見的防火墻之一,但客戶指出,安裝和部署過程并不順利,通常需要專業服務或支持團隊的幫助。
? Marketing Strategy: Check Point continues to market Infinity as both an architecture and an ELA around the concept of generational threat protection (currently Gen V). Gartner clients express confusion around this messaging and which solutions the vendor can provide to help protect their environment. Check Point lacks strong positioning and product messaging.
? 市場策略:Check Point繼續將Infinity作為一個架構和一個ELA圍繞代際威脅保護(目前為Gen V)的概念進行營銷。Check Point缺乏強大的定位和產品信息。
? Technical Support: Gartner clients continue to cite that Level 3 escalations take longer than Level 1 and Level 2 escalations, and that the vendor lacks in timely updated communication while the team is working on it.
? 技術支持:Gartner客戶繼續指出,第3級升級比第1級和第2級升級耗時更長,并且在團隊進行升級時,供應商缺乏及時更新的溝通。
Cisco
Cisco is a large network, infrastructure and security vendor, based in San Jose, California. It continues to offer multiple firewall models for different use cases, although many models under the different firewall product lines overlap with each other. Cisco firewalls continue to be part of large Cisco infrastructure deals. Gartner does observe the vendor being shortlisted by existing Cisco clients as one of the firewall vendors. Its vision of cloud and automation, if executed well, can help the vendor gain traction in related use cases.
思科是一家大型網絡、基礎設施和安全供應商,總部位于加州圣何塞。它繼續為不同的用例提供多個防火墻模型,盡管不同防火墻產品線下的許多模型相互重疊。思科防火墻仍然是思科大型基礎設施交易的一部分。Gartner確實注意到該供應商被現有的思科客戶列為防火墻供應商之一。它對云和自動化的愿景,如果執行良好,可以幫助供應商在相關用例中獲得牽引力。
Cisco’s security product portfolio includes many solutions, including firewalls, and it has grown continually over the past few years, mainly through acquisitions. It offers endpoint security client Cisco AMP, Cisco AnyConnect (*
client), Stealthwatch and Stealthwatch Cloud (network traffic analysis [NTA]), secure web gateway (SWG), email security, network access control and a CASB — with Talos threat intelligence included with Cisco security products.
思科的安全產品組合包括許多解決方案,包括防火墻。在過去幾年里,思科主要通過收購不斷發展壯大。它提供端點安全客戶端Cisco AMP, Cisco AnyConnect (*客戶端),Stealthwatch和Stealthwatch云(網絡流量分析[NTA]),安全網絡網關(SWG),電子郵件安全,網絡訪問控制和一個CASB -包括Talos威脅情報思科安全產品。
Cisco continues to sell multiple firewall product lines: Cisco Adaptive Security Appliance (ASA) 5500-X Series and Adaptive Security Virtual Appliance (ASAv), its virtual firewall appliances; Cisco Firepower NGFW Series, which also exists in the form of virtual appliances (NGFWv); the Meraki MX series; and Cisco IOS Firewall. The vendor also offers two industrial firewalls (the ISA series).
思科繼續銷售多個防火墻產品線:思科自適應安全設備(ASA) 5500-X系列和自適應安全虛擬設備(ASAv),其虛擬防火墻設備;思科火力NGFW系列,也以虛擬設備(NGFWv)的形式存在;Meraki MX系列;和思科IOS防火墻。供應商還提供了兩個工業防火墻(ISA系列).
Cisco Umbrella is the vendor’s cloud DNS security and secure web gateway. Cisco Tetration started as cloud visibility software, and recently evolved into an agent-based firewall for application and microsegmentation.
思科傘是供應商的云DNS安全和安全的網絡網關。Cisco Tetration最初是云可視化軟件,最近發展成為一個基于代理的應用和微分割防火墻。
Cisco Threat Response (CTR) is the Cisco web portal for threat investigation, adding context and an indicator of compromises to events sent from registered Cisco security products.
思科威脅響應(CTR)是思科威脅調查的門戶網站,為注冊的思科安全產品發送的事件添加上下文和危害指標。
The vendor continues its effort to build a unified centralized management console with Cisco Defense Orchestrator (CDO), which aims at managing all of its firewall product lines. The Cisco Meraki MX series also offers cloud-based management targeting distributed organization use cases.
供應商繼續努力,以建立一個統一的集中式管理控制臺與思科防御編配(CDO),旨在管理其所有的防火墻產品線。Cisco Meraki MX系列還提供了針對分布式組織用例的基于云的管理。
Firepower Management Center (FMC) is Cisco’s on-premises centralized management offering, available for Cisco ASA 5500-X and Firepower devices only.
火力管理中心(FMC)是思科的現場集中管理產品,僅適用于思科ASA 5500-X和火力設備。
Strengths
? Sales Execution: Cisco’s global footprint is a big asset when trying to convince large organizations to purchase its firewalls and adjacent security products. Gartner analysts see a large number of organizations signing ELAs with Cisco, including for a large number of Cisco Firepower firewalls. Many clients describe themselves as “Cisco shops.”
? 銷售執行:當試圖說服大型組織購買思科的防火墻和鄰近的安全產品時,思科的全球足跡是一項巨大的資產。Gartner分析師認為,許多組織與思科簽署了ELAs協議,其中包括思科的大量火力防火墻。許多客戶將自己描述為“思科商店”。
? Marketing Execution: Cisco owns a broad portfolio of network and security solutions. Gartner sees the vendor enthusiastically promoting the integration and automation roadmap within its products as a strong marketing and sales strategy, which is also resonating with end users. It is also an attractive proposition for clients that want to consolidate toward a single vendor.
? 市場執行:思科擁有廣泛的網絡和安全解決方案。Gartner認為,供應商熱情地在其產品中推廣集成和自動化路線圖,這是一種強有力的營銷和銷售策略,也引起了終端用戶的共鳴。對于希望向單個供應商合并的客戶來說,這也是一個有吸引力的建議。
? During inquiries, Gartner clients mention the Cisco integration story among the different Cisco products as a primary reason for the purchase.
? 在詢問中,Gartner的客戶提到了思科不同產品之間的集成故事,這是購買的主要原因。
? Capability: Customers and resellers continue to give high scores to Talos threat research and to advanced malware protection (AMP) features available on Firepower. Existing Sourcefire customers also like the IDPS integration on Firepower.
? 能力:客戶和經銷商繼續給予高度評價Talos威脅研究和先進的惡意軟件保護(AMP)功能可用的火力。現有的Sourcefire客戶也喜歡集成在“火力”上的IDPS。
? Capability: Cisco Meraki MX appeals to distributed organizations looking for ease of deployment and maintenance. Cisco Meraki MX’s proprietary auto-*
and SD-WAN simplify site-to-site deployments when using only Meraki devices.
? 能力:Cisco Meraki MX呼吁尋求部署和維護的簡便性的分布式組織。Cisco Meraki MX的專有自動
和SD-WAN在僅使用Meraki設備時簡化了站點到站點的部署。
? Feature: The Cisco AnyConnect
client offers support for most mobile devices and their OSs. Gartner constantly receives inquiries in which clients rate the offered by the vendor as higher compared to other vendors. They state that the tunnels are stable and users do not experience disconnected sessions. Many Gartner clients that replace their Cisco ASAs with a firewall from a different vendor continue to use ASAs for only.
? 特點:思科AnyConnect
客戶端為大多數移動設備及其操作系統提供支持。Gartner經常收到客戶的詢問,其中客戶對供應商提供的的評價高于其他供應商。他們表示隧道是穩定的,用戶不會經歷斷開的會話。許多Gartner的客戶用來自不同供應商的防火墻替換了他們的Cisco as,他們仍然只將ASAs用于*。
Cautions
? Project Execution: While Cisco has made progress on its competitive positioning, it struggles to win firewall evaluation against other competitors in pure firewall deals based on technical evaluation alone. This puts Cisco in a difficult spot when the three vendors offer similar prices, which is more frequent than in the past due to recent pricing strategy changes from Cisco and its competitors.
? 項目執行:雖然思科在競爭定位上取得了進展,但在純粹的基于技術評估的防火墻交易中,思科很難從其他競爭對手那里贏得防火墻評估。當這三家供應商提供類似的價格時,思科陷入了一個困難的境地。由于思科及其競爭對手最近改變了定價策略,這種情況比以往更加頻繁。
? Product Execution: Cisco clients that have purchased multiple Cisco security products with Cisco Firepower firewall to utilize integration and automation capabilities, as highlighted by the vendor at the time of sales, are often disappointed when they don’t work in their environment. Gartner clients often cite the lack of automation between Cisco ISE (NAC solution) and Cisco Firepower as quite frustrating. Gartner highly recommends that clients evaluate the integration capabilities between different Cisco products before purchase.
? 產品執行:Cisco的客戶購買了多個Cisco安全產品,并使用了Cisco的“火力防火墻”來利用集成和自動化功能,正如供應商在銷售時強調的那樣,當他們不能在自己的環境中工作時,常常會感到失望。Gartner的客戶經常說,思科的ISE (NAC解決方案)和思科的“火力”之間缺乏自動化是非常令人沮喪的。Gartner強烈建議客戶在購買之前評估對比不同思科產品之間的集成能力。
? Product Execution: Cisco Meraki MX, Firepower and, increasingly, Viptela can be relevant in overlapping use cases for distributed organizations with SD-WAN requirements. As the three solutions do not have full feature parity, prospective clients and Cisco resellers struggle to build an architecture when it needs to combine multiple solutions. CDO is still a work in progress and lacks fully featured unified management, which could help with the issue.
? 產品執行:Cisco Meraki MX、和Viptela在具有SD-WAN需求的分布式組織的重疊用例中可能越來越重要。由于這三種解決方案沒有完全的功能對等,潛在客戶和思科經銷商在需要組合多個解決方案時,很難構建架構。CDO還在進行中,缺乏全功能的統一管理,這有助于解決問題。
? Capabilities: Cisco Firepower lacks SD-WAN features and zero-touch deployment. Gartner observes that Cisco clients are less likely to use application control, TLS decryption and URL filtering features. Surveyed customers also express frustration with the lack of comprehensive real-time logging and reporting solutions.
? 能力:思科火力缺乏SD-WAN功能和零接觸部署。Gartner指出,思科客戶不太可能使用應用程序控制、TLS解密和URL過濾功能。被調查的客戶還對缺乏全面的實時日志記錄和報告解決方案表示失望。
? Geographic Strategy: Gartner is noticing declining visibility of Cisco firewalls in pure firewall deals outside North America in client inquiries. The vendor is more visible in other regions as part of large Cisco infrastructure deals. Gartner has also observed more focus by the vendor on expanding the Cisco Meraki MX product line in the U.S. and U.K.
? 地理戰略:Gartner注意到,思科防火墻在北美以外的客戶咨詢業務中,純防火墻業務的可看性正在下降。作為思科大型基礎設施交易的一部分,思科在其它地區的知名度更高。Gartner還注意到,思科更加注重在美國和英國擴展思科Meraki MX產品線
? Capabilities: Cisco clients continue to complain about their inability to effectively deploy Firepower virtual machines on IaaS platforms. They mention stability issues and feature inconsistencies. Gartner also does not see Cisco being deployed on public cloud, compared to competitors.
? 功能:思科客戶繼續抱怨他們無法有效地在IaaS平臺上部署火力虛擬機。他們提到穩定性問題和特性的不一致性。與競爭對手相比,Gartner也認為思科不會部署在公共云上。
? Customer Experience: Cisco scored lower than average on surveyed customers’ satisfaction with quality of support. This aligns with what Gartner analysts observe during client inquiries, where the ability to get timely answers has been reported as degrading over time, especially when facing issues with centralized management features.
? 客戶體驗:思科在客戶對支持質量的滿意度調查中得分低于平均水平。這與Gartner分析師在客戶咨詢過程中觀察到的情況一致,據報道,及時獲得答案的能力會隨著時間的推移而下降,尤其是在集中管理功能出現問題時。
? Capability: Cisco Firepower’s management API lags in maturity behind its direct competitors. This has noticeable consequences, such as delays in support from network security policy management tools (NSPM), and the absence of integration, notably with any third-party endpoint detection and response (EDR) tools.
? 能力:思科“火力”的管理API在成熟度上落后于其直接競爭對手。這帶來了明顯的后果,比如網絡安全策略管理工具(NSPM)的支持延遲,以及缺乏集成,特別是與任何第三方端點檢測和響應(EDR)工具的集成。
F5
F5, based in Seattle, Washington, is a leading data center application delivery controller vendor. It continues to focus on data center and CSP use cases for its firewall module deployment. Clients using F5 or procuring application delivery products for the vendor should consider using the firewall module offered by the vendor. The primary use case for using the vendor’s firewall is vendor consolidation, higher throughput requirements and advanced routing capabilities.
位于華盛頓州西雅圖的F5是一家領先的數據中心應用程序交付控制器供應商。它繼續專注于數據中心和CSP用例的防火墻模塊部署。使用F5或為供應商采購應用程序交付產品的客戶應考慮使用供應商提供的防火墻模塊。使用供應商防火墻的主要用例是供應商整合、更高的吞吐量需求和高級路由功能。
F5’s Advanced Firewall Manager (AFM) module, as a part of its BIG-IP appliances, is sometimes visible in the vendor’s quotations with other products offered. Gartner comes across existing F5 clients that want to evaluate the firewall capabilities offered by the vendor with other firewall vendors in the market. F5 firewalls have limited visibility in data centers and large enterprise deployment.
F5的高級防火墻管理器(AFM)模塊作為其BIG-IP設備的一部分,有時可以在供應商提供的其他產品的報價中看到。Gartner遇到過一些現有的F5客戶端,他們希望與市場上的其他防火墻供應商一起評估該供應商提供的防火墻功能。F5防火墻在數據中心和大型企業部署中可見性有限。
F5’s security portfolio includes a WAF solution, access policy manager (APM), web fraud protection (WebSafe), and a DDoS mitigation solution, DDoS Hybrid Defender (DHD). Under the Silverline brand, F5 delivers a cloud WAF and DDoS protection. Its firewall product relies on the BIG-IP appliances (21 models, from 5 Gbps up to 320 Gbps) and VIPRION chassis (six models, up to 1.2TB throughput) hardware platforms, running the F5 Traffic Management Operating System (TMOS). F5 also offers 11 virtual appliances (F5 Virtual Editions [VE]) and centralized management (BIG-IQ) for its BIG-IP solutions.
F5的安全組合包括WAF解決方案、訪問策略管理器(APM)、web欺詐保護(WebSafe)和DDoS緩解解決方案、DDoS混合防御器(DHD)。在Silverline品牌下,F5提供了云WAF和DDoS保護。其防火墻產品依賴于大ip設備(21個型號,從5 Gbps到320 Gbps)和VIPRION底盤(6個型號,最高1.2TB吞吐量)硬件平臺,運行F5流量管理操作系統(TMOS)。F5還為其BIG-IP解決方案提供11個虛擬設備(F5虛擬版本[VE])和集中管理(BIG-IQ)。
Recent product news includes multiple enhancements related to routing, traffic inspection and DDoS mitigation.
最近的產品新聞包括與路由、流量檢查和DDoS緩解相關的多個增強。
Strengths
? Product Strategy: F5’s software is optimized for data center and ISP infrastructure protection use cases with its highly scalable architecture, native load balancing support and focus on carrier-grade issues such as carrier-grade network address translation (CGNAT) and DDoS capabilities.
? 產品策略:F5的軟件針對數據中心和ISP基礎設施保護用例進行了優化,具有高度可伸縮的體系結構、本地負載平衡支持,并專注于電信級問題,如電信級網絡地址轉換(CGNAT)和DDoS功能。
? Feature: The vendor offers strong load balancing and DDoS mitigation capabilities. This offers clients the ability to consolidate firewall functionality with mature application delivery and security capabilities. However, all the features come as separate products with dedicated subscriptions.
? 特性:該供應商提供強大的負載平衡和DDoS緩解功能。這為客戶提供了利用成熟的應用程序交付和安全功能來整合防火墻功能的能力。但是,所有的功能都是單獨的產品,并且有專門的訂閱。
? Customer Experience: F5’s customers report better-than-average satisfaction with the vendor’s technical support. Customers also report above-average performance of the F5 firewall, and cite performance and throughput as key deciding factors when selecting F5 for their firewall.
? 客戶體驗:F5的客戶對供應商技術支持的滿意度高于平均水平。客戶還報告說F5防火墻的性能高于平均水平,并將性能和吞吐量作為選擇F5作為防火墻的關鍵決定因素。
? Product Strategy (IaaS): F5 partners with multiple public IaaS cloud service providers including Alibaba, AWS, Azure, Google Cloud Platform, IBM and Oracle, making it a desirable shortlist candidate for mutlicloud deployments.
? 產品戰略(IaaS): F5與多個公共IaaS云服務提供商合作,包括阿里巴巴、AWS、Azure、谷歌云平臺、IBM和Oracle,使其成為多云部署的理想候選。
? Product: F5 offers strong TLS decryption in its BIG-IP appliance, as well as a dedicated TLS decryption appliance (SSL Orchestrator). F5 fully supports RFC 8446 TLS 1.3 decryption in TMOS 14.1.0.1 and higher, well ahead of many other firewall vendors, making SSL decryption capabilities stronger than the competitors.
? 產品:F5在其大ip設備中提供強大的TLS解密,以及專用的TLS解密設備(SSL編制器)。F5完全支持TMOS 14.1.0.1及更高版本的RFC 8446 TLS 1.3解密,遠遠領先于許多其他防火墻廠商,使SSL解密能力強于競爭對手。
? Geographic Presence: F5 is a long-established application delivery vendor with a large, loyal global channel. The vendor also has a direct presence through regional offices worldwide. This makes it a strong global vendor.
? 地理位置:F5是一個歷史悠久的應用程序交付供應商,擁有一個大型的、忠誠的全球渠道。該供應商還通過全球區域辦事處直接開展業務。這使它成為一個強大的全球供應商。
Cautions
? Sales Execution: F5 rarely appears on Gartner client competitive shortlists for enterprise firewall selection, and often complements other firewalls rather than replacing them. In addition, there has been significant turnover in its sales leadership, impacting reseller relationships over the past year.
? 銷售執行:F5很少出現在Gartner客戶端競爭企業防火墻的候選名單上,通常是對其他防火墻的補充,而不是取代它們。此外,在過去的一年里,其銷售領導層出現了很大的人員流動,影響了經銷商之間的關系。
? Customer Experience: F5’s customers generally report satisfaction with its product, but are reluctant to provide unqualified recommendations of it due to a lack of common firewall features, which prevents it from being used in certain use cases such as end-user perimeter firewalls. Surveyed clients have reported more reliance on the vendor’s professional services because of a lack of sufficient product documentation and steep learning curve as product limitations.
? 客戶體驗:F5的客戶通常對其產品表示滿意,但不愿提供不合格的建議,因為缺乏通用的防火墻功能,這阻止了它在某些用例中被使用,比如終端用戶周邊的防火墻。被調查的客戶報告更多地依賴于供應商的專業服務,因為缺乏足夠的產品文檔和陡峭的學習曲線作為產品的局限性。
? Product: The F5 firewall lacks advanced threat detection features such as anti-malware and sandboxing, native or third-party endpoint security integration, and support for SD-WAN, which are commonly provided by vendors competing in the enterprise firewall market.
? 產品:F5防火墻缺乏先進的威脅檢測功能,如反惡意軟件和沙箱、本地或第三方端點安全集成,以及對SD-WAN的支持,這些功能通常由企業防火墻市場上的競爭廠商提供。
? Product Strategy: F5 does not offer a set of low-end appliances, a multitenant FWaaS option, NAC integration or cloud-based management consoles, and tends to focus its products on carrier-grade networks and large enterprise internal data center use cases. Unlike other vendors in the market, the network team is most likely to manage F5 due to its integration with the application delivery controller and, therefore, may not be managed or considered by security teams for firewall use cases.
? 產品策略:F5不提供一組低端設備、多租戶FWaaS選項、NAC集成或基于云的管理控制臺,其產品往往集中于電信級網絡和大型企業內部數據中心用例。與市場上的其他供應商不同,網絡團隊最有可能管理F5,因為它與應用程序交付控制器集成,因此,對于防火墻用例,安全團隊可能不會管理或考慮F5。
? Market Responsiveness: F5 includes an IDPS feature based on a limited number of SNORT signatures. Gartner advises that customers looking for high-security, network-based intrusion prevention solutions augment the F5 IDPS because it is not as robust or mature as other offerings seen in the network firewall market today.
? 市場響應性:F5包含一個基于有限數量的SNORT簽名的IDPS特性。Gartner建議,尋求高安全性、基于網絡的*
防御解決方案的客戶會增加F5的IDPS,因為它不像目前網絡防火墻市場上看到的其他產品那樣健壯或成熟。
Forcepoint準能科技
Forcepoint is a security vendor headquartered in Austin, Texas. Its firewalls continue to be visible primarily in distributed office use cases where clients are looking for mature SD-WAN, and centralized management capabilities. Gartner sees good potential in the firewall to meet other use cases, but sees a delay in market responsiveness and a lack of focus to expand the customer base beyond distributed office use cases by Forcepoint.
Forcepoint是一家總部位于德克薩斯州奧斯汀的安全供應商。它的防火墻仍然主要出現在分布式辦公用例中,在這些用例中,客戶正在尋找成熟的SD-WAN、
和集中式管理功能。Gartner認為防火墻具有滿足其他用例的良好潛力,但它認為市場響應能力較差,并且缺乏通過Forcepoint將客戶基礎擴展到分布式辦公用例之外的重點。
The vendor offers a firewall (Forcepoint NGFW), web and email security gateways (Forcepoint Web Security and Forcepoint Email Security), data loss prevention (Forcepoint DLP), an insider threat solution (Forcepoint Insider Threat), a cloud access security broker (Forcepoint CASB), and user and entity behavior analytics (Forcepoint UEBA). It also offers government-specific security solutions.
供應商提供防火墻(Forcepoint NGFW)、web和電子郵件安全網關(Forcepoint web安全和Forcepoint電子郵件安全)、數據丟失預防(Forcepoint DLP)、內部威脅解決方案(Forcepoint內部威脅)、云訪問安全代理(Forcepoint CASB)和用戶和實體行為分析(Forcepoint UEBA)。它還提供針對政府的安全解決方案。
Virtual Forcepoint firewalls offer support for Azure and AWS, where they are available, as pay as you go as well.
Virtual Forcepoint防火墻提供了對Azure和AWS的支持,只要你愿意,隨時都可以使用它們。
Forcepoint’s recent news includes the introduction of five new compact desktop models. Other updates include support for new, compact desktop models (33x and 5x series), and feature enhancements for SD-WAN and networking. Support for auto-scaling and management for its visual firewalls with virtualized environments (AWS, Azure, VMware, etc.) is available.
Forcepoint的最新消息包括推出五款新的小型臺式電腦。其他更新包括對新的、緊湊的桌面模型(33x和5x系列)的支持,以及對SD-WAN和網絡的功能增強。支持使用虛擬環境(AWS、Azure、VMware等)自動擴展和管理其可視化防火墻。
Strengths
? Market Execution: The majority of the installed base for Forcepoint firewalls with mature and SD-WAN capabilities is in distributed office use cases. Even the vendor is keen to focus on this use case by continually introducing more enhancements for and SD-WAN.
? 市場執行:具有成熟和SD-WAN功能的Forcepoint防火墻的安裝基礎主要是在分布式辦公用例中。甚至供應商也熱衷于關注這個用例,不斷地為和SD-WAN引入更多的增強功能。
? Product: Security Management Center (SMC), which is the vendor’s centralized management offering, is very intuitive and easy to use. SMC is available as a management appliance, management appliance ISO image and software.
? 產品:安全管理中心(SMC),是供應商的集中管理產品,非常直觀,易于使用。SMC是一種可用的管理設備,管理設備ISO映像和軟件。
? It offers features such as drag and drop, which is very smooth. SMC provides granular administrator access control. Administrator roles can be defined, and mapped with select NGFWs, access control lists and Domains. There is also an administrator privilege for approving pending changes with features such as drag and drop. Surveyed clients have also highly rated SMC and scored it higher in ease of management.
? 它提供了拖放等功能,非常平滑。SMC提供細粒度的管理員訪問控制。管理員角色可以通過選擇NGFWs、訪問控制列表和域來定義和映射。管理員還可以使用拖放等特性批準掛起的更改。接受調查的客戶也對SMC給予了很高的評價,并在管理便利性方面給予了更高的分數。
? Feature (IDPS): The vendor has a legacy reputation of mature IDPS offers. Forcepoint utilizes threat intelligence from McAfee GTI and the Lastline reputation service, in addition to Forcepoint TI. Forcepoint firewalls offers best-of-breed firewall clustering capabilities, with a mature load balancing capability between different appliance models and running different firmware. Surveyed clients have also highly rated the firewall clustering capabilities, which are easy to manage and failover is transparent to the network.
? 特性(IDPS):該供應商擁有成熟IDPS產品的傳統聲譽。Forcepoint利用來自McAfee GTI和Lastline聲譽服務的威脅情報,此外還有Forcepoint TI。Forcepoint防火墻提供了最好的防火墻集群功能,在不同的設備模型和運行不同的固件之間具有成熟的負載平衡功能。被調查的客戶還高度評價了防火墻的集群功能,這些功能易于管理,而且故障轉移對網絡是透明的。
? Automation: Forcepoint offers cloud provisioning tools and automated scripts for DevOps use cases. The vendor offers public GitHub project SMC Python and SMC integration for Ansible.
? 自動化:Forcepoint為DevOps用例提供云供應工具和自動化腳本。供應商為Ansible提供公共GitHub項目SMC Python和SMC集成。
? Feature (): Forcepoint firewalls offer easy-to-configure templates. The vendor has a large installed base of multiple branch office use cases. The UI offers easy-to-monitor-and-manage multiple tunnels.
? 特性(): Forcepoint防火墻提供易于配置的模板。該供應商擁有一個龐大的多分支機構用例的安裝基礎。UI提供了易于監視和管理的多個隧道。
? Capability: The vendor offers built-in UEBA capabilities, bringing advanced threat detection capabilities beyond network sandboxing without the need for an additional subscription. The Forcepoint firewall platform collects data from network engines (physical/software/virtual/cloud variants), endpoint intelligence agents and via Syslog feeds from other third-party solutions deployed within an organization.
? 功能:該供應商提供內置的UEBA功能,帶來了超越網絡沙箱的高級威脅檢測功能,不需要額外的訂閱。Forcepoint防火墻平臺從網絡引擎(物理/軟件/虛擬/云變體)、端點情報代理和組織內部署的其他第三方解決方案的Syslog提要收集數據。
Cautions
? Market Execution: Forcepoint sells multiple product lines, out of which Web Security, its SWG product, seems to be the primary product where most R&D work is focused. Gartner finds that the vendor focuses less on its firewall product line as a result, keeping it confined to distributed office use cases. While Gartner thinks that Forcepoint has good experience and a good R&D team, the firewall has the potential to be one of the industry leaders if the vendor focused more toward this product line.
? 市場執行:Forcepoint銷售多個產品線,其中其SWG產品Web Security似乎是大多數研發工作重點關注的主要產品。Gartner發現,供應商因此較少關注其防火墻產品線,從而將其限制在分布式辦公用例中。雖然Gartner認為Forcepoint有良好的經驗和良好的研發團隊,但如果供應商更關注這個產品線,防火墻有潛力成為行業領導者之一。
? Marketing: Forcepoint lacks strong marketing of its firewall products; as a result, it does not have much visibility on client shortlists. Despite the firewall offering mature threat detection capabilities, the marketing team markets its SD-WAN and capabilities most of the time, resulting in a lack of awareness within the end-user base.
? 營銷:Forcepoint防火墻產品營銷力度不夠;因此,它在客戶入圍名單上的可見度不高。盡管防火墻提供了成熟的威脅檢測功能,但營銷團隊大部分時間都在推銷其SD-WAN和
功能,導致終端用戶缺乏意識。
? Offering: The vendor lacks EDR client integration capabilities. It also lacks firewall integration with third-party EDR clients.
? 產品:該供應商缺乏EDR客戶端集成功能。它也缺乏與第三方EDR客戶端的防火墻集成。
? Product Strategy: Despite having a strong client base and a focus on distributed office use cases, the vendor does not offer a cloud-based management portal, as offered by most competitors. The vendor also lacks FWaaS, despite offering multiple other cloud-based product lines.
? 產品策略:盡管擁有強大的客戶基礎和對分布式辦公用例的關注,但是該供應商并沒有像大多數競爭對手那樣提供基于云的管理門戶。該供應商還缺乏FWaaS,盡管提供了多個其他基于云的產品線。
? Customer Feedback: Surveyed clients have reported that the vendor’s Level 1 support is not competent enough to deal with common support issues and escalates them further, creating longer escalation cycles.
? 客戶反饋:接受調查的客戶報告稱,供應商的一級支持不足以處理常見的支持問題,并將其進一步升級,從而形成更長的上升周期。
Fortinet 飛塔
Fortinet is a network and security player, headquartered in Sunnyvale, California. This year, Fortinet firewalls continue to be visible in distributed office deals where integrated SD-WAN is the primary selection criterion. They are also seen as replacing dedicated routers and act as an edge appliance with firewalls. Fortinet is also a favorable firewall shortlist for customers that cite pricing as an important selection criterion. The vendor offers a range of firewall models to meet multiple firewall deployment use cases. It also offers support for bare metal and virtual firewalls for Alibaba Cloud, AWS, Azure, Google Cloud Platform, IBM Cloud and Oracle OCI IaaS platforms.
Fortinet是一家網絡和安全公司,總部位于加州森尼韋爾。今年,在集成SD-WAN為主要選擇標準的分布式辦公協議中,Fortinet防火墻繼續可見。它們也被視為替代專用路由器,并充當防火墻的邊緣設備。對于那些將價格作為重要選擇標準的客戶來說,Fortinet也是一個不錯的防火墻候選名單。該供應商提供了一系列防火墻模型,以滿足多個防火墻部署用例。它還為阿里巴巴提供裸金屬和虛擬防火墻支持
The other products in Fortinet’s portfolio cover network security, endpoint security, security information and event management (SIEM), NAC, wireless access points and switches. FortiGate firewalls are still the vendor’s most popular and best-selling product.
Fortinet的其他產品包括網絡安全、端點安全、安全信息和事件管理(SIEM)、NAC、無線接入點和交換機。FortiGate防火墻仍然是該供應商最受歡迎和最暢銷的產品。
In 2018 and 2019, Fortinet introduced new FortiGate models 6000F, 3600E, 3400E, 600E and 400E Series. It also had two major firmware releases with enhancements for the FortiGate firewall, new SD-WAN ASIC, virtual security processors, and centralized management and reporting software. It continues to work toward integration through APIs and security fabric.
在2018年和2019年,Fortinet推出了新的防御模型6000F、3600E、3400E、600E和400E系列。它還發布了兩個主要的固件版本,其中增強了防御防火墻、新的SD-WAN ASIC、虛擬安全處理器以及集中管理和報告軟件。它繼續通過api和安全結構進行集成。
Strengths
? SD-WAN: Fortinet offers integrated SD-WAN capabilities within its E-Series firewalls, which makes it a favorable shortlist candidate for distributed enterprise use cases. It comes with capabilities like application-based routing, especially for SaaS applications like Office 365 that are easy to configure. The vendor also offers features such as multipath automated failover for specific applications based on health performance, latency, jitter and packet loss, which enhance the performance of the applications.
? SD-WAN: Fortinet在其e系列防火墻中提供了集成的SD-WAN功能,這使它成為分布式企業用例的理想候選。它具有基于應用程序的路由等功能,特別是對于易于配置的SaaS應用程序(如Office 365)。該供應商還提供基于健康性能、延遲、抖動和包丟失的特定應用程序的多路徑自動故障轉移等特性,這些特性增強了應用程序的性能。
? SSL Decryption: This year, Fortinet introduced support for TLS 1.3 in the FortiOS 6.2 release. This feature enhances existing deeper inspection capabilities for the Web Filter profile with flow-based inspection mode enabled and for the SSL/SSH Inspection profile.
? SSL解密:今年,Fortinet在FortiOS 6.2版本中引入了對TLS 1.3的支持。該特性通過啟用基于流的檢查模式增強了Web篩選器概要文件和SSL/SSH檢查概要文件現有的更深層次的檢查功能。
? Integration: Fortinet continues to extend integration capabilities using security fabric and APIs with AWS, Azure, Google Cloud Platform and Alibaba, and develops tools to offer automation. Some of the capabilities include security fabric integration using AWS Lambda, and automatically updating dynamic addresses for AWS using Fabric Connectors. The vendor also offers playbooks for integration of Ansible and Terraform modules.
? 集成:Fortinet繼續使用安全架構和api與AWS、Azure、谷歌云平臺和阿里巴巴進行集成,并開發提供自動化的工具。一些功能包括使用AWS Lambda的安全fabric集成,以及使用fabric連接器為AWS自動更新動態地址。供應商還提供了Ansible和Terraform模塊集成劇本。
? Geographic Presence: FortiGate firewalls continue to be visible on Gartner client firewall shortlists in different regions, competing with regional players. Regional players have also citied Fortinet as one of the top three competitors for them locally.
? 地理位置:在不同地區的Gartner客戶端防火墻候選名單上,加強防火墻仍然可見,與地區玩家競爭。區域玩家也認為Fortinet是他們在當地的三大競爭對手之一。
? Sales Execution: Fortinet works closely with many MSSPs globally that are offering Fortinet firewalls as hosted services to their clients. The vendor has specific licensing models for its VM-Series appliances specific to MSSPs. FortiManager and FortiAnalyzer also offer multiple multitenancy features that can be extended using APIs.
? 銷售執行:Fortinet與全球許多mssp密切合作,為其客戶提供Fortinet防火墻托管服務。供應商為其特定于mssp的vm系列設備提供特定的許可模型。FortiManager和FortiAnalyzer還提供了多種可以使用api擴展的多租戶特性。
? Licensing: While the majority of Gartner clients generally complain about complex licensing by most enterprise-grade firewall vendors, Fortinet has maintained its simpler licensing by offering bundle-based licensing, which is easier to understand and renew for end users.
? 授權許可:盡管Gartner的大多數客戶通常抱怨大多數企業級防火墻供應商提供的復雜授權許可,但Fortinet通過提供基于捆綁的授權許可來保持其更簡單的授權許可,這對終端用戶來說更容易理解和更新。
Cautions
? Visibility: Despite support for multiple cloud IaaS platforms, FortiGate is not visible on Gartner client shortlists as a preferred firewall on IaaS platforms, compared to prominent competitors that have more visibility in this use case.
? 可見性:盡管支持多種云IaaS平臺,但在Gartner客戶端候選名單上,FortiGate作為IaaS平臺上的首選防火墻是不可見的,相比之下,在這個用例中,一些著名的競爭對手有更多的可見性。
? Product: Although Fortinet offers security fabric and API integration capabilities for integration of its products, it lacks mature direct integration capabilities of its firewalls with other security products in the portfolio for threat correlation.
? 產品:雖然Fortinet提供了用于集成其產品的安全結構和API集成功能,但它缺乏將其防火墻與投資組合中的其他安全產品進行直接集成以進行威脅關聯的成熟功能。
? The vendor offers basic visibility into infected hosts and their vulnerabilities through FortiClient as a dashboard widget, but lacks mature direct threat correlation capabilities with FortiGate. FortiManager and FortiManager Cloud lack the management controls of FortiWeb, FortiSIEM and FortiCASB.
? 該供應商通過FortiClient作為一個儀表板小部件提供受感染主機

向AI問一下細節

免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。

AI

玉树县| 南城县| 景德镇市| 海兴县| 南郑县| 双流县| 福安市| 香河县| 兰西县| 濉溪县| 洛隆县| 泰宁县| 元谋县| 图片| 本溪市| 永新县| 遂宁市| 曲靖市| 博野县| 达拉特旗| 河曲县| 民乐县| 思南县| 盐边县| 黔江区| 城口县| 保康县| 绥阳县| 开化县| 孟村| 应城市| 长治县| 阿拉尔市| 广元市| 四平市| 陕西省| 宣城市| 石阡县| 泽普县| 泗洪县| 稻城县|