Hardware firewalls are dedicated security appliances with embedded software
that deliver highest levels of security, performance and reliability. These
appliances provide robust security services including stateful packet
inspection, standards-based IPSec, VPN, intrusion detection and protection in
cost-effective solutions that are relatively easy to implement.
Connecting to the Internet without a firewall is an invitation to hackers.
Hackers can easily enter your system, steal valuable data and even take control
of computers to engage in Internet attacks on other systems or use the SMTP
servers for flooding the world with millions of e-mails. A hacker attack, even a
blind attack — where the hacker does not even know the host, can cost your
customer lakhs (or even crores) of rupees worth of business.
Hardware firewalls are more effective than software firewalls mainly on two
counts — they don't slow down the system and hackers cannot crash them
remotely. Moreover, as the Internet access passes through the hardware firewall
itself, even if a hacker manages to crash your hardware firewall, he can't
reach inside your network because then there is no way to get into your network.
SELECTING THE RIGHT FIREWALL
Many varieties of hardware firewalls are now available, from those that come
in small plastic boxes for the SOHO users for a few thousand rupees, to those
that come in rack mounted black-boxes with gigabit firewalls for the more
demanding enterprise and service provider environments, costing lakhs of rupees.
Some firewalls come in specialized versions like anti-spam and anti-virus
firewalls. These dedicated firewalls available for fighting spam and viruses can
handle over 10 million e-mail messages a day, without bogging down your mail
servers. They can also filter out viruses at the same time.
These firewalls reduce the load on email servers as they operate
independently and stop the junk from reaching the mail server. A spam and virus
firewall with live update facility can take care of the attacks from latest
viruses.
Once plugged between the Internet and the network, the firewall can handle
denial of service security protection, IP block list, rate controls, protection
from viruses and block spam according to predefined spam blocking rules, user
specified rules, spam fingerprint check and Bayesian analysis.
WHY A HARDWARE MAKES SENSE
Hardware firewalls provide robust security services including stateful
packet inspection, standards-based IPSec, VPN, intrusion detection and
protection and much more cost-effective solutions that are relatively easy to
implement.
High-end models intended for large enterprise and service provider
environments, provide over 1 Gbps of firewall throughput with the ability to
handle up to 500,000 concurrent connections. They can provide support for 2,000
IPSec tunnels.
Other models can provide from 10 Mbps at the lower end to over 360 Mbps of
firewall throughput at the higher end with the ability to handle over 200,000
simultaneous sessions at the higher end.
These firewalls can provide a wide range of security and networking services
including Network Address Translation (NAT), Port Address Translation (PAT),
content filtering (Java/ActiveX), URL filtering, AAA (RADIUS/TACACS+)
integration, support for leading X.509 PKI solutions, DHCP client/server, PPPoE
support and much more. They can also provide advanced security services for
multimedia applications and protocols including Voice over IP (VoIP).
Web-based management interfaces are generally available with the firewalls
along with centralized, policy-based management tools to support for remote
monitoring protocols like Simple Network Management Protocol (SNMP). The
firewalls can also be managed using a convenient Command-line Interface (CLI)
through a variety of methods including Telnet, Secure Shell (SSH) and an
out-of-band console port.
BUILT-IN ROUTERS
Hardware-based firewalls are also available as firewall-routers with
built-in VPN router function. Equipped with embedded VPN support, they can
create multiple IPSec tunnels to remote offices. Strong encryption with DES,
3DES, and automated key management via IKE/ISAKMP give added security.
A VPN tunnel can be activated to a remote office for a secured traffic flow
between the two locations for mobile users using triple DES Encryption. This
offers users a way to confidentially access and transfer sensitive information.
Multiple VPN tunnels may be easily created without the need to setup Internet
Key Exchange policies. URL blocking, logs of real-time Internet traffic, alarms
of Internet attacks, and notice of web-browsing activities can be reported
through e-mail notification.
Hardware appliances can allow unlimited number of network clients without the
cost of additional licensing fees for the clients, generally charged by some
software vendors.
OTHER FEATURES
Some other important features offered by hardware firewalls include
Detect/Drop intruding packets from denial of service and hacker attacks,
embedded VPN, DMZ port, multiple-mapped IPs, multiple virtual servers, and
server load balancing.
A Demilitarized Zone port allows Web servers, mail servers and FTP servers to
be accessed from the Internet. This particular feature is useful because it
diverts congested server traffic from the Internal network.
Some firewall appliances can operate with a Smartcard key, without which they
will not allow any data to pass through it. They are not based on a PC and
cannot be configured remotely.
In fact, users of the network will not know that the firewall is there.
Because it will not respond to network messages, it cannot be interfered with.
Only the Smartcard Key holds the setup information, and the outside world has no
access to it.
The Smartcard Key is programmed using a special programming device that plugs
into the COM port of a standard PC. A Key Cutter program enables selection of
packet types, protocols, filters, ports and services that you want to allow. The
Smartcard Key can also be programmed for address translation to enable the 'Inner
World' addresses to be hidden from the "Outer World".
Even with this type of firewalls, there has to be a well designed security
policy and the person responsible for cutting the Smartcard Key will need to
know what the security policy is, what the structure of the network is and have
a clear idea of which parts he wants to protect and from what.
Ashok Dongre is an independent
consultant
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us