Palo Alto, CheckPoint, SonicWall, BarracudaNG, FortiNET, Is not a PacketViper!

Posted: October 10, 2013 in Cyber Security, Geo IP Filtering, Network Attacks, Network Security, PacketViper, Product Comparison
Time and time again the question is asked “How Does PacketViper compare to a <Insert Firewall Name Here>?

We explain what we do, compared to what they do.  The very next sentence is We can do that now with <Insert Firewall Name Here>

Can you Really?

I’m going to explain the differences between <Insert Firewall Name Here> and PacketViper. What you have to keep in mind is PacketViper is designed to remove the traffic before entering the security environment. It quickly eliminates unwanted traffic to improve the performance throughout the entire security environment.  PacketViper’s sits inline, fail-open bypass, transparent Geo IP layer has a significant positive impact to every gateway, spam filter, mail and web servers, VPN portals, and so on. It immediately hardens even the most exposed networks with a few clicks, and no complex configuration.

Although many want to compare us to <Insert Firewall Name Here>, we are in the security layer to to help them work more efficiently. Our layer can do many different things which they can not offer because of their Layer3+ inspections. if you activated every feature to its fullest on <Insert Firewall Name Here>, what would the latency cost be to your traffic? I would say pretty great, not to mention log and alert overload, false positives, troubleshooting connection issues, and customer complaints.

Technically we are a firewall, but <Insert Firewall Name Here> is not a PacketViper,

CheckPoint IPS blade note from a commentator ” Please Note enabling the perform all IPS inspection on all traffic, can have a adverse effect on the performance of the firewall”

1. PacketViper is a inline appliance or software that operates transparent, and adds no network hop to the packet.

2. PacketViper looks “only” at the header information of the packet.  This is how we keep near wire speeds, negligible latency, and yet provide better details.

Explanation: PacketViper keeps its high performance by only looking at the header information that is then matched to our Geo Location database. <Insert Firewall Name Here> runs the packet through a gambit of tests, checks, patterns, and anything else you can imagine.

3. PacketViper is very simple to filter out unwanted country traffic.

Explanation:  PacketViper is one of the simplest devices to use, to filter unwanted traffic into the environment.  Looking at the <Insert Firewall Name Here> configuration is a challenge. I understand the devil is in the details, but when you are being flooded with email, web requests, DDoS, dictionary attacks, probes, or NMAP’s on a daily basis, so to us the devil is the common sense.  Do you really need someone from some country probing your VPN port? You see some firewall vendors show statements like;

4. PacketViper Triggers to prevent DDoS, By Country, Company, Network, IP, or Port.

5. PacketViper blocks countries by ports.

Explanation: Even though blocking a country is not new, the way we do it is. We do not just filter the country but rather the country, its ports bi-directionally, and some.  It is so simple with PacketViper you will wonder how this can be.  I found one video from Fortinet that was tolerable. The others would just lose you in the details trying to block a country at a port.

If you take a look at everything these super firewall and IDS systems do, it would amaze and awe anyone, until you get into them.  Like looking down from space at the earth its breathtaking. Until you get to the ground to find billions roadways, buildings, offices, rooms, closets, and alcoves. – Francesco Trama

6.  PacketViper can quickly redirect traffic based on the source IP, network, country, or Global Network List.

Explanation:  DNat is not a new thing, but with PacketViper you have a much more common sense method, and more details.

Aside from a constant labor intensive management, false positives, log overload, and long learning curve with complex firewalls. They are an absolute MUST in the security environment.  Which ever one you choose or have chosen, PacketViper will eliminate the pressure to and through them.  PacketViper eliminates the unwanted traffic hereby freeing up valuable bandwidth, and resources. PacketViper improves the entire security layer by removing the unwanted traffic through them.

