Firewall Software and Hardware: A Comparative Overview
This paper provides a comprehensive introduction to computer firewalls, covering their definition, underlying principles, and primary categories—including network layer, application layer, and proxy-based firewalls. It then profiles three major vendors: Symantec, Zone Labs, and Cisco Systems. Drawing on those profiles, the paper recommends specific products for three distinct network scenarios: a small LAN with no publicly accessible resources, a small LAN hosting one public-facing website, and a large organization running an e-commerce site with resources accessed by strategic partners. The paper concludes that product selection should be driven by the scale, exposure level, and management complexity of the target environment.
- Firewall Overview: Definition and core function of firewalls
- Types of Firewalls: Personal, network layer, application layer, and proxy types
- Major Software and Hardware Firewall Manufacturers: Profiles of Symantec, Zone Labs, and Cisco
- Best Products for a Small LAN Without Publicly Accessible Resources: Norton Personal Firewall and ZoneAlarm Pro recommendations
- Best Products for a Small LAN With One Publicly Accessible Website: Cisco PIX Firewall as recommended solution
- Best Products for Large Organizations With E-Commerce and Partner Access: Symantec Enterprise Firewall for complex environments
- Conclusion: Summary of firewall selection by deployment scenario
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper moves logically from foundational concepts to applied product recommendations, giving readers the context they need before evaluating specific solutions.
- It uses direct quotations from industry sources and vendor documentation to ground claims about product capabilities, adding credibility to what could otherwise be purely descriptive writing.
- The three-scenario framework (small LAN, small LAN with public site, large enterprise) gives the paper a clear practical structure that maps directly to real-world decision-making.
Key academic technique demonstrated
The paper demonstrates applied comparative analysis: it establishes evaluation criteria early (protection scope, self-protection, compliance tools, integration) and then uses those criteria implicitly when recommending specific products for each scenario. This prevents the product sections from reading as mere advertisements and ties recommendations back to the analytical framework established in the overview.
Structure breakdown
The paper opens with a definition-driven overview that introduces both hardware and software firewalls, then distinguishes personal from traditional firewalls and network layer from application layer types. A vendor profiles section follows, covering Symantec, Zone Labs, and Cisco. The final three sections each address a distinct deployment scenario, matching a recommended product to a specific organizational context. The references section lists all sources in APA format.
Firewall Overview
To determine which firewall products are most appropriate for a given scenario, one must first understand what a firewall is. "The security experts say a firewall is a dedicated machine that checks every network packet passing through, and that either drops or rejects certain packets based on rules set by the system administrator" (Wouters, 1997). Beyond this hardware-based definition, the development of firewall applications has expanded the concept to include anything—hardware or software—that performs the filtering of packets.
Firewalls have "the basic task of controlling traffic between different zones of trust" ("Firewall (networking)," 2005). These zones typically include the Internet and an internal network. The Internet is generally defined as a zone with no trust, while an internal network is typically a zone of high trust. The goal of a firewall is to control connectivity between these differing levels of trust.
Types of Firewalls
There are two types of firewalls that are usually distinguished. A personal firewall is a software application that filters traffic entering and exiting a single computer. A traditional firewall most often runs on a dedicated device and is positioned between two or more networks, filtering all traffic entering and exiting those connected networks ("Firewall (networking)," 2005).
Within traditional firewalls, there are two primary categories: network layer firewalls and application layer firewalls. Organizations may choose to overlap these two categories. "Network layer firewalls operate at a relatively low level of the TCP/IP protocol stack as IP-packet filters, not allowing packets to pass through the firewall unless they match the rules" ("Firewall (networking)," 2005). These rules can be established by the firewall administrator or can be default rules built into less flexible firewall systems. Network firewalls are now often built into many operating systems and network appliances.
The other category of traditional firewalls is application layer firewalls. These work on the application level of the TCP/IP stack, which encompasses all browser traffic, all Telnet traffic, and all FTP traffic. They intercept packets traveling between applications. In theory, application layer firewalls can stop unwanted outside traffic from ever reaching the protected machine. "By inspecting all packets for improper content, firewalls can even prevent the spread of viruses. In practice, however, this becomes so complex and so difficult to attempt—given the variety of applications and the diversity of content each may allow in its packet traffic—that comprehensive firewall design does not generally attempt this approach" ("Firewall (networking)," 2005).
A proxy device may also act as a firewall by responding to input packets like an application while blocking others. These devices make it difficult for someone to tamper with an internal system via an external network. "Misuse of one internal system would not necessarily cause a security breach exploitable from outside the firewall, as long as the application proxy remains intact and properly configured. Conversely, intruders may hijack a publicly reachable system and use it as a proxy for their own purposes; the proxy then masquerades as that system to other internal machines" ("Firewall (networking)," 2005).
There are several considerations to keep in mind when choosing a personal firewall for an enterprise environment. First, one must consider whether complete protection is offered. This includes inbound protection—where the firewall opens PC ports only for authorized network traffic, blocks intrusion attempts, and hides endpoint PCs from port scans—as well as outbound protection to prevent unauthorized applications and malicious code from capturing and sending enterprise data to hackers. E-mail protection must be offered in the form of quarantining suspicious attachments and protecting address books from hijackers. Instant message protection and custom security zones should also be offered to "segment network traffic and restrict access on trusted LANs while maintaining high security for Internet connections" (Silver & Pescatore, 2004).
The second consideration is whether the firewall can protect itself. Hackers often try to disable firewalls; therefore, a comprehensive firewall should include protection against being disabled, tamper resistance so hackers cannot alter a firewall's configuration, and protection against application spoofing (Silver & Pescatore, 2004).
A firewall should also offer compliance tools to enforce policy compliance. This includes up-to-date comprehensive enforcement criteria, enforcement of the presence or absence of specific parameters, and enforcement on endpoints independent of access method. There must also be integration with all leading gateway vendors and centralized enforcement reporting (Silver & Pescatore, 2004).
Major Software and Hardware Firewall Manufacturers
There are several notable firewall manufacturers, including those who offer software solutions and those who offer hardware solutions. Symantec is one of the leading information security providers in the world. Founded in 1982, Symantec's objective is to "be a trusted security partner for individuals and enterprises around the world" ("Symantec corporate," n.d.).
With approximately 6,000 employees, Symantec offers a wide variety of software, appliances, and services designed to help everyone from individuals to large organizations secure and manage their IT infrastructure. The company has operations in more than 35 countries and provides security products, services, and solutions to more than 120 million users around the globe ("Symantec corporate," n.d.).
With threats to information systems growing in both number and complexity, enterprise customers know that hardening network perimeters alone is not enough. Symantec provides best-of-breed security solutions for all tiers of a network: at the gateways between the network and the outside world, at the servers that act as the network's vital organs, and at end-user devices including desktop PCs, laptops, and handhelds ("Symantec corporate," n.d.). This includes firewall solutions designed to protect data and assets without degrading network performance.
Zone Labs is another leading provider of firewall technology. They supply Internet security to everyone from individual consumers to global enterprises. "Zone Labs is a leading creator of endpoint security solutions protecting millions of PCs, and the valuable, personally identifiable information on those PCs, from hackers, spyware, and data theft" ("About Zone," 2005).
Cisco Systems is perhaps the largest company specializing in networking for the Internet. Cisco Internet Protocol-based networking solutions are the foundation of most leading business, education, government, and private networks. "Cisco hardware, software, and service offerings are used to create Internet solutions that allow individuals, companies, and countries to increase productivity, improve customer satisfaction, and strengthen competitive advantage" ("News @ Cisco," 2005).
Cisco was founded in 1984 and has since grown to become the industry leader in the development of Internet Protocol-based networking technologies, with a consistent focus on networking innovation. With more than 34,000 employees worldwide, Cisco offers a variety of products and services that create smarter, faster, and more secure networks ("News @ Cisco," 2005).
Conclusion
As computers continue to play an increasingly vital role in both personal and business life, selecting the right firewall product for a given environment is essential. For small LANs with no public-facing resources, consumer-grade solutions such as Norton Personal Firewall 2005 and ZoneAlarm Pro offer ease of use alongside solid protection. For small LANs hosting a single public website, the Cisco PIX Firewall provides scalable, stateful protection. For large organizations managing e-commerce operations and partner access, Symantec Enterprise Firewall delivers the deep packet inspection, centralized management, and blended-threat protection that complex environments demand. Ultimately, matching the firewall product to the scale and exposure level of the network is the most important factor in any security decision.
References
About Zone Labs. (2005). Retrieved March 13, 2005, from http://www.zonelabs.com/store/content/company/aboutUs/aboutUs.jsp
Cisco PIX 500 Series firewall. (2005). Retrieved March 13, 2005, from http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/index.html
Cisco PIX firewall software. (2005). Retrieved March 13, 2005, from http://www.cisco.com/en/US/products/sw/secursw/ps2120/index.html
Firewall (networking). (2005, March 13). Retrieved March 13, 2005, from http://en.wikipedia.org/wiki/Firewall_%28networking%29
Firewall/VPN. (2005). Retrieved March 13, 2005, from
Key features: Norton Personal Firewall 2005. (n.d.). Retrieved March 13, 2005, from
News @ Cisco. (2005). Retrieved March 13, 2005, from
Norton Personal Firewall 2005. (n.d.). Retrieved March 13, 2005, from
Silver, M., & Pescatore, J. (2004, August 12). Choosing a personal firewall for enterprise PCs using Windows XP. Retrieved March 13, 2005, from http://www.zonelabs.com/store/content/company/corpsales/solutionXPSP2.jsp
Symantec corporate information. (n.d.). Retrieved March 13, 2005, from
Symantec Enterprise Firewall. (2005). Retrieved March 13, 2005, from
Wouters, P. (1997, August). Designing a safe network using firewalls. Linux Journal, 40. Retrieved March 13, 2005, from the ACM Digital Library database.
ZoneAlarm Pro. (2005). Retrieved March 13, 2005, from http://www.zonelabs.com/store/content/catalog/products/zap/zap_details.jsp?lid=ho_zap
Always verify citation format against your institution’s current style guide requirements.