Skip to Content

The Firewall Dilemma in Mid-Sized Business

Anyone buying a firewall for a small or medium-sized business faces a difficult choice. This lesson describes three impositions that keep coming up when firewalls are purchased. It also explains why pure open source is not an easy way out for many companies.

The three impositions of buying a firewall

Firewall procurement sounds like a technical decision. In practice it is mostly an economic and legal decision. Three points cause trouble again and again.

1. The license stack

On top of the actual box come subscriptions, individual feature licenses and support contracts. Each of these items has its own term and its own price development. Anyone who adds up the total cost after three years often finds a sum that barely resembles the original offer.

2. Cloud dependency and foreign jurisdiction

Many large vendors manage their firewalls through their own cloud. The management interface and telemetry data then run through data centers outside Europe. A company's own security infrastructure ends up depending on a foreign jurisdiction and on the business decisions of a foreign vendor. For a company that wants to protect its own data, that is a contradiction.

3. Hardware lock-in

With many vendors the software is tied firmly to a specific box. When the company grows or traffic grows, the old appliance no longer has enough capacity. A new purchase follows, along with new licensing and new training. The firewall does not grow with the company, it has to be replaced.

Why pure open source is often not a way out

At this point some IT managers consider a pure open source solution. That solves the licensing question, but it brings its own risks. A pure open source firewall comes without a guarantee. There is no service level agreement that promises a response time in an emergency. And there is no fixed contact person who can be reached when something breaks. For a test system that may be enough. For a production environment that protects a company's entire network traffic, few IT departments can carry that risk permanently.

Key point: A firewall tied to one box does not grow with the company. Sooner or later it has to be replaced.
Key point: Pure open source without a guarantee, an SLA and a contact person is a risk that few companies want to take on knowingly in production.

Why this matters for AIMdefense

These three impositions are the starting point for the development of AIMdefense. How AIMdefense actually resolves them is the subject of the next lesson in this course.

Commenting is not enabled on this course.