Vendor Landscape: Next Generation Firewall
Continued consolidation of capabilities means high performing products.

Introduction
Network security is still a high priority for organizations; the right perimeter means more threats stay outside and sensitive data remains inside.

This Research Is Designed For:
This Research Will Help You:
• Enterprises seeking to select a solution for Next Generation Firewall (NGFW). Their NGFW use case may include:
  - Enterprises looking for a network perimeter security appliance for comprehensive protection of the network edge.
  - Enterprises that have established their network perimeter NGFW strategy independently and need guidance in evaluating available products.
• Understand what's new in the NGFW market.
• Evaluate NGFW vendors and products for your enterprise needs.
• Determine which products are most appropriate for particular use cases and scenarios.

Executive summary
Info-Tech evaluated ten competitors in the NGFW market, including the following notable performers:

Champions:
• Dell (SonicWALL) has the full package – great features and price.
• Fortinet: a consistent leader in the firewall space.
• WatchGuard: a strong product for organizations with a strict budget.
• Sophos: one of the only products evaluated with a full feature set.

Value Award: WatchGuard has a highly competitive price for organizations looking for a comprehensive product without spending the dollars.

Trend Setter Award: WatchGuard: the product's reporting functions were a differentiator amongst other NGFWs.

Info-Tech Insight
1. Protect outbound data as well as inbound.
Built-in Data Leakage Protection (DLP) capabilities ensures that sensitive or confidential data is protected.

2. The more traffic your firewall can see, the better it can protect it.
Encrypted traffic can conceal threats from firewalls, while Wi-Fi networks provide a route for attacks to bypass firewalls. Today's firewall solutions focus on controlling these types of traffic.

3. Capabilities should not cut down on performance.
Despite the breadth of features, NGFW should not have a significant impact to your overall network performance, even if you have the capabilities fully "switched on."

Market overview

How it got here
• Firewalls originated theoretically in the late 1980s before being brought to fruition as traffic-controlling tools.
• Firewalls have evolved four times over from simple packet filters (that evaluated source, destination, and protocol) to stateful inspectors (with the capability of "remembering" the nature of ongoing communications and origin of the packets involved), proxies (evaluated packet contents, rather than just the packets), to Unified Threat Management systems (UTMs) or Next Generation Firewalls (NGFWs).
• The last iteration – originating as the term UTM – began integrating capabilities such as anti-malware and intrusion prevention for a more robust firewall.
• While there is still debate over the semantics, UTMs are now frequently referred to as Next Generation Firewalls.

Where it's going
• NGFWs reflect a movement towards more content aware security, combining additional capabilities on top of anti-malware and intrusion prevention, such as:
  o Data Leakage Protection (DLP)
  o Network Access Control (NAC)
  o Application control
  o User identity-related control
• A growing number of vendors are also adding web application firewalling functionality.
• As more organizations seek out consolidated solutions for economical savings and resource management, NGFW will be replacing most standalone security solutions like DLP. Some vendors have already started phasing out standalones this year.

As the market evolves, capabilities that were once cutting edge become default and new functionality becomes differentiating. Intrusion prevention has become a Table Stakes capability and should no longer be used to differentiate solutions. Instead focus on DLP and web application control to get the best fit for your requirements.

NGFW vendor selection / knock-out criteria: market share, mind share, and platform coverage

While there is some debate over semantics regarding UTM vs. NGFW, the market remains stable, represented by long-time, experienced vendors and newer, but just as strong, competitors. For this Vendor Landscape, Info-Tech focused on those vendors that offer broad capabilities across multiple platforms and that have a strong market presence and/or reputational presence among mid and large-sized enterprises.

Included in this Vendor Landscape:
• Barracuda. Highly competitive solution in terms of features and the space's best kept secret.
• Check Point. One of the progenitors of the firewall space and still one of the most recognizable names.
• Cisco. The ASA firewall line remains one of the strongest solutions, coupled with Cisco's networking market share.
• Dell (SonicWALL). After being acquired by Dell in 2012, it has emerged as one of the stronger solutions features-wise.
• Fortinet. The vendor that coined the UTM term and one of the first to incorporate enhanced capabilities.
• Juniper. Entered the firewall market through acquisition of NetScreen and has established a solid foothold since then.
• McAfee. NGFW is another piece to the security giant's already broad portfolio of products.
• Palo Alto. The most recent entrant to the market of the reviewed solutions, but still offering a competitive solution.
• Sophos. Acquired Cyberoam in 2014 to bolster its NGFW portfolio.
• WatchGuard. Another vendor growing into larger markets after an early focus in the SMB space.

NGFW criteria & weighting factors

Product Evaluation Criteria
Features: The solution provides basic and advanced feature/functionality.
Usability: The end-user and administrative interfaces are intuitive and offer streamlined workflow.
Affordability: Implementing and operating the solution is affordable given the technology.
Architecture: Multiple deployment options and extensive integration capabilities are available.

Criteria
Product 50%

Vendor Evaluation Criteria
Viability: Vendor is profitable, knowledgeable, and will be around for the long term.
Strategy: Vendor is committed to the space and has a future product and portfolio roadmap.
Reach: Vendor offers global coverage and is able to sell and provide post-sales support.
Channel: Vendor channel strategy is appropriate and the channels themselves are strong.

Vendor 50%
Viability 25%
Strategy 30%
Channel 30%
Reach 15%

The Info-Tech NGFW Vendor Landscape

The zones of the Landscape
Champions receive high scores for most evaluation criteria and offer excellent value. They have a strong market presence and are usually the trend setters for the industry.

Market Pillars are established players with very strong vendor credentials, but with more average product scores.

Innovators have demonstrated innovative product strengths that act as their competitive advantage in appealing to niche segments of the market.

Emerging Players are comparatively newer vendors who are starting to gain a foothold in the marketplace. They balance product and vendor attributes, though score lower relative to competitors.

[Vendor positioning chart showing:]
Champions: Dell (SonicWALL), Fortinet, WatchGuard
Market Pillars: Cisco, Check Point
Innovators: Sophos, Barracuda
Emerging Players: Juniper, Palo Alto, McAfee

Balance individual strengths to find the best fit for your organization

[Table showing vendor ratings across Features, Usability, Affordability, Architecture, Viability, Strategy, Reach, and Channel for:]
Barracuda
Check Point*
Cisco
Fortinet
Juniper*
Intel (McAfee)*
Palo Alto*
Dell (SonicWALL)
Sophos
Watchguard

Legend: Exemplary, Good, Adequate, Inadequate, Poor
*The vendor declined to provide pricing and publicly available pricing could not be found.

The Info-Tech NGFW Value Index

What is a Value Score?
The Value Score indexes each vendor's product offering and business strength relative to its price point. It does not indicate vendor ranking.

Vendors that score high offer more bang-for-the-buck (e.g. features, usability, stability, etc.) than the average vendor, while the inverse is true for those that score lower.

Price-conscious enterprises may wish to give the Value Score more consideration than those who are more focused on specific vendor/product attributes.

On a relative basis, WatchGuard maintained the highest Info-Tech Value ScoreTM of the vendor group. Vendors were indexed against WatchGuard's performance to provide a complete, relative view of their product offerings.

[Value Index scores:]
WatchGuard: 100
Dell (SonicWALL): 85
Sophos: 92
Barracuda: 80
Fortinet: 42
Cisco: 28
Juniper: 26
Check Point: 60
Palo Alto: 11
McAfee: 0

Average Score: 52

*The vendor declined to provide pricing and publicly available pricing could not be found.

Table Stakes represent the minimum standard; without these, a product doesn't even get reviewed

The Table Stakes
Feature | What it is:
Firewall | The solution includes a stateful inspection.
VPN | Offers IPSEC (for site-to-site tunnels) and SSL VPN (for remote access) options.
Anti-Malware | Built-in perimeter anti-virus and anti-spyware protection.
Intrusion Prevention | Ability to recognize and restrict inappropriate and unauthorized access.

What does this mean?
The products assessed in this Vendor LandscapeTM meet, at the very least, the requirements outlined as Table Stakes.

Many of the vendors go above and beyond the outlined Table Stakes, some even do so in multiple categories. This section aims to highlight the products' capabilities in excess of the criteria listed here.

If Table Stakes are all you need from your NGFW solution, the only true differentiator for the organization is price. Otherwise, dig deeper to find the best price to value for your needs.

Advanced Features are the capabilities that allow for granular market differentiation

Scoring Methodology
Info-Tech scored each vendor's features offering as a summation of its individual scores across the listed advanced features. Vendors were given one point for each feature the product inherently provided. Some categories were scored on a more granular scale with vendors receiving half points.

Advanced Features
Feature | What we looked for:
Identity-Based Control | Mapping of specific security policies to defined user groups and individuals.
Data Leakage Protection | Restriction on the egress of sensitive privileged or confidential data.
Network Access Control | Endpoint integration to ensure each connecting device has appropriate security.
URL Filtering | Restrictive filtering of web surfing to limit exposure to harmful and inappropriate sites.
Application Control | Ability to restrict, on a granular level, which web apps are allowed to run.
Wi-Fi Network Control | Ensuring Wi-Fi networks have the same security stance and abilities as the perimeter.
WAN Routing & Optimization | Dynamic routing of WAN traffic backed by QoS and prioritization capabilities.
Encrypted Data Control | Native decryption and re-encryption of SSL and SFTP traffic for thorough inspection.
Web App Firewalling | Ability to protect web servers against attacks like SQL injections.

Each vendor offers a different feature set; concentrate on what your organization needs

Evaluated Features
[Table showing feature presence for each vendor across:]
Identity, DLP, WCF, App Control, App FW, NAC, Wi-Fi, WAN, Encryption

Barracuda
Check Point
Cisco
Fortinet
Juniper
McAfee
Palo Alto
Dell (SonicWALL)
Sophos
WatchGuard

Legend: Feature fully present, Feature partially present/pending, Feature absent

Beyond traffic, data also deserves protection and NGFW have incorporated such capabilities

Solutions with either DLP, web application control, and encryption, or just web application control and encryption, will inspect and control your data.

Why Scenarios?
In reviewing the products included in each Vendor LandscapeTM, certain use cases come to the forefront. Whether those use cases are defined by applicability in certain locations, relevance for certain industries, or as strengths in delivering a specific capability, Info-Tech recognizes those use cases as Scenarios, and calls attention to them where they exist.

Scenario 1: Enhanced inbound traffic protection
Customer requires DLP, web app control, & encryption
[Vendors: Sophos, Dell (SonicWALL)]

Scenario 2: Customer has DLP; requires Web app control & encryption
[Vendors: Barracuda, Check Point, Cisco, Fortinet, Juniper, McAfee, Palo Alto, WatchGuard]

Dell (SonicWALL) is one of the best all-around solutions, along with being one of the most affordable

Headquarters: Round Rock, TX
Website: dell.com
Founded: 1991
Presence: NASDAQ:DELL
Products: SuperMassive Series, NSA Series, TZ Series
Employees: 100,000+

3 year TCO for this solution falls into pricing tier 5, between $50,000 and $100,000
Pricing provided by vendor

After Dell's acquisition of SonicWALL in 2012, Dell leveraged its existing presence to establish a strong NGFW strategy.

Strengths
• The Dell (SonicWALL) NGFW Series has a strong feature set, missing only NAC.
• The product's interface was one of the best of the solutions evaluated. It was interactive, featuring an attractive and useful geographical map to show where the firewalls were located. It also included data transfer reporting to see what it was costing the organization by day (ideal for demonstrating product effectiveness). Many of the offered reporting options were also attractive.

Challenges
• Currently the NGFW series is only available through hardware and virtual deployments, limiting the options organizations have for their NGFW.

The SuperMassive, NSA, and TZ series all offer one of the strongest feature sets in this evaluation

Vendor Scorecard:
Product: Features, Usability, Affordability, Architecture
Vendor: Viability, Strategy, Reach, Channel
Overall: 3rd

Value Index: 85 (3rd out of 10)

FW Throughput Ranges:
TZ Series: TZ 105/W, TZ 205/W, TZ 215/W (200-800 Mbps)
NSA Series: NSA 220W, NSA 250M/W (500-3000 Mbps)
SuperMassive Series: (4000-40000 Mbps)
Solutions range from 200 Mbps to 40 Gbps

Features:
Identity ✓
DLP ✓
WCF ✓
App Control ✓
App FW ✓
NAC ✗
Wi-Fi ✓
WAN ✓
Encryption ✓

Info-Tech Recommends:
The one downside to the otherwise stellar Dell (SonicWALL)'s firewalls is that they currently only offer hardware and virtual deployment options. But for organizations that want a highly competitive and affordable solution, Dell (SonicWALL)'s firewall products are ideal choices.

Fortinet offers a best all-around NGFW solution

Headquarters: Sunnyvale, CA
Website: fortinet.com
Founded: 2000
Presence: NASDAQ:FTNT
Products: FortiGate NGFW
Employees: 2,300+

3 year TCO for this solution falls into pricing tier 5, between $50,000 and $100,000
Pricing provided by vendor

Fortinet helped define the UTM space with its original FortiGate. Fortinet's firewalls still remain its strongest product, even with its expanded portfolio.

Strengths
• Fort

FortiGate NGFW is feature rich, with flexible deploymentoptionsVendor rd.Arch.OverallViabilityStrategyReachChannelSocial Features for Customer ServiceFW Throughput RangesFW Throughput Ranges15010008001006004005020000100D30DValue Index424th out of 10MbpsGbpsSolutions range from800 Mbps to 120 GbpsFeaturesIdentityDLPWCFApp ControlApp FWNACWi-FiWANEncryptionInfo-Tech Recommends:Fortinet’s FortiGate solution is ideal for organizations looking for a lot of bells and whistles, along with thebudget to afford it. The solution also offers a range of deployment possibilities from cloud-ready optionsto Amazon Web Services.Vendor Landscape: NGFWInfo-Tech Research Group17

WatchGuard’s XTM series is the best bangfor any organization’s :Website:Founded:Presence: WatchGuard strongly, through no longer exclusively, focuses onthe firewalling needs of the SMB space. The company is strongand the products able.XTM Series400 Seattle, WAwatchguard.com2006Privately HeldStrengths WatchGuard’s XTM series offers the best bang-for-your-buck withan affordable price for a solid and scalable product. The XTM firewall can provide reports from different levels(executive dashboard, security dashboard, threat map, etc.), andeach dashboard includes various components that are clickable toprovide detailed event information in an attractive way – adifferentiator amongst its competitors.3 year TCO for this solution falls into pricingtier 5, between 50,000 and 100,000Challenges The XTM series is missing some key advanced features such asweb application firewalling and NAC. 1 2.5M Pricing provided by vendorVendor Landscape: NGFWInfo-Tech Research Group18

WatchGuard’s affordability is unprecedented in this evaluationVendor rd.Arch.OverallViabilityStrategyReachChannelSocial Features for Customer ServiceXTM 5 SeriesXTM 800 Series1543102510Value Index1001st out of 100XTM515XTM525XTM535XTM545XTM XTM XTM850 860 870GbpsGbpsWatchGuard recommended the 5 Series and the 800 Series for our pricing scenario, so the ranges are spec’d out here. The 5Series ranges from 2 Gbps to 3.5 Gbps. The 800 Series ranges from 8 bps to 14 Gbps.FeaturesIdentityDLPWCFApp ControlApp FWNACWi-FiWANEncryptionInfo-Tech Recommends:With a solid advanced features set and the right price, WatchGuard’s XTM series also offers goodscalability, making it a good choice for any-sized organization looking to stay within a budget.Vendor Landscape: NGFWInfo-Tech Research Group19

Sophos’ SG Series’ full feature set and high performancemakes it a rs:Website:Founded:Presence:SG Series2,200 Oxford, UK & Boston, MAsophos.com1985Privately Held Acquired NGFW company, Cyberoam, in 2014 demonstrating itsincreased focus on the firewall space, as they also transition to thehigh performance SG Series.Strengths Sophos SG Series has a full advanced features set – meaning allof the capabilities are there if you want all features (such as DLP,web application firewalling, etc.) turned on your NGFW. The SG Series interface is highly configurable for networkdefinitions, offers bandwidth control, a wide range of reportingoptions, drag-an