<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data Center Firewall - Monolithic vs Virtualized in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/data-center-firewall-monolithic-vs-virtualized/m-p/286420#M76590</link>
    <description>&lt;P&gt;This is purely theoretical and does not represent a real network.&lt;/P&gt;&lt;P&gt;You can think of this as on prem or public cloud:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Monolithic&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;This design utilizes 3 physical firewalls that are embedded in a data center fabric&lt;BR /&gt;• Perimeter&lt;BR /&gt;• B2B&lt;BR /&gt;• DC&lt;BR /&gt;The main focus of my question is on the DC firewall, as you can see segmentation is derived by using traditional zones. There are some people that like this design as its very simple and it has been used for years.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DC Firewall - monolithic.jpg" style="width: 957px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21254i3DF8359DE04A83B4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DC Firewall - monolithic.jpg" alt="DC Firewall - monolithic.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Virtualization&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;This design utilizes 3 physical firewalls that are embedded in a data center fabric&lt;BR /&gt;• Perimeter&lt;BR /&gt;• B2B&lt;BR /&gt;• Virtualized (vfw’s)&lt;BR /&gt;The main focus of my question is on the Virtualized firewall, as you can see segmentation is derived by creating virtualized firewalls that represent the Environment that we are trying to segment. There are some people that like this design as it provides greater audit capabilities on environments like PCI x and y -&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DC Firewall - virtualization.jpg" style="width: 957px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21256i94C56522EC46184B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DC Firewall - virtualization.jpg" alt="DC Firewall - virtualization.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide a short paragraph on what your thoughts are – what do you see as the pro’s and con’s to each design.&lt;/P&gt;&lt;P&gt;Which one is better for on prem?&lt;/P&gt;&lt;P&gt;Which one is better for public cloud?&lt;/P&gt;&lt;P&gt;Which one would provide better audit capabilities?&lt;/P&gt;&lt;P&gt;Which one would provide better automation / orchestration capabilities?&lt;/P&gt;&lt;P&gt;Which one is more agile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DC Firewall - virtualization.jpg" style="width: 0px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21255iA6EA7233F208BBAD/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" width="0" height="0" role="button" title="DC Firewall - virtualization.jpg" alt="DC Firewall - virtualization.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2019 21:30:29 GMT</pubDate>
    <dc:creator>mcronin</dc:creator>
    <dc:date>2019-09-03T21:30:29Z</dc:date>
    <item>
      <title>Data Center Firewall - Monolithic vs Virtualized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-center-firewall-monolithic-vs-virtualized/m-p/286420#M76590</link>
      <description>&lt;P&gt;This is purely theoretical and does not represent a real network.&lt;/P&gt;&lt;P&gt;You can think of this as on prem or public cloud:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Monolithic&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;This design utilizes 3 physical firewalls that are embedded in a data center fabric&lt;BR /&gt;• Perimeter&lt;BR /&gt;• B2B&lt;BR /&gt;• DC&lt;BR /&gt;The main focus of my question is on the DC firewall, as you can see segmentation is derived by using traditional zones. There are some people that like this design as its very simple and it has been used for years.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DC Firewall - monolithic.jpg" style="width: 957px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21254i3DF8359DE04A83B4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DC Firewall - monolithic.jpg" alt="DC Firewall - monolithic.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Virtualization&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;This design utilizes 3 physical firewalls that are embedded in a data center fabric&lt;BR /&gt;• Perimeter&lt;BR /&gt;• B2B&lt;BR /&gt;• Virtualized (vfw’s)&lt;BR /&gt;The main focus of my question is on the Virtualized firewall, as you can see segmentation is derived by creating virtualized firewalls that represent the Environment that we are trying to segment. There are some people that like this design as it provides greater audit capabilities on environments like PCI x and y -&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DC Firewall - virtualization.jpg" style="width: 957px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21256i94C56522EC46184B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DC Firewall - virtualization.jpg" alt="DC Firewall - virtualization.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide a short paragraph on what your thoughts are – what do you see as the pro’s and con’s to each design.&lt;/P&gt;&lt;P&gt;Which one is better for on prem?&lt;/P&gt;&lt;P&gt;Which one is better for public cloud?&lt;/P&gt;&lt;P&gt;Which one would provide better audit capabilities?&lt;/P&gt;&lt;P&gt;Which one would provide better automation / orchestration capabilities?&lt;/P&gt;&lt;P&gt;Which one is more agile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DC Firewall - virtualization.jpg" style="width: 0px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21255iA6EA7233F208BBAD/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" width="0" height="0" role="button" title="DC Firewall - virtualization.jpg" alt="DC Firewall - virtualization.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 21:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-center-firewall-monolithic-vs-virtualized/m-p/286420#M76590</guid>
      <dc:creator>mcronin</dc:creator>
      <dc:date>2019-09-03T21:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Firewall - Monolithic vs Virtualized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-center-firewall-monolithic-vs-virtualized/m-p/286605#M76629</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51263"&gt;@mcronin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which one is better for on prem?&lt;/P&gt;&lt;P&gt;Which one is better for public cloud?&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Stop thinking of the "cloud" and on-prem networks differently, because they aren't. The "cloud" is generally when we can get away with making the most amount of changes without major disruption because the environments are just getting built out, so most people will have more isolation in the "cloud" environment. This isn't because it's needed, it's because more people actually get to redesign their environments with a proper segmented design.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Which one would provide better audit capabilities?&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Anytime you gain more insight into the traffic, you'll have better audit abilities. In your diagram it doesn't appear like the virtualized design as seperating the different groups into different zones, so your Monolithic design actually allows more insight into the traffic and therefore allows you to better audit connections.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Which one would provide better automation / orchestration capabilities?&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;They are both the same. You would have a more complex environment with multiple virtualized firewalls over a single firewall with additional zones, but your automation abilities are the same if you have one firewall or multiple.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Which one is more agile ?&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Define agile. The virtualized diagram that you have would be better suited for a move into micro-segmentation in the furture, which should really be what you are aiming for.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 16:58:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-center-firewall-monolithic-vs-virtualized/m-p/286605#M76629</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-04T16:58:50Z</dc:date>
    </item>
  </channel>
</rss>

