Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 2003

SOAP/XML Firewalls

Web services require more protection than traditional firewalls offer
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    The Promise of Web Services

Firewall Implementations
Vendors can implement SOAP/XML firewalls either as an appliance or through server-side software on the Web server. Both approaches have trade-offs. Because appliances are designed and optimized for one purpose, they usually offer better throughput. Appliances such as Westbridge Technology's Westbridge XA2500 Security and Management Appliance and DataPower Technology's XS40 XML Security Gateway promise wire-speed processing of traffic and better reliability than server-side software. The Reactivity XML Firewall acts as a proxy that you deploy in the demilitarized zone (DMZ). Forum Systems' Forum Sentry 1500 appliance supports several deployment modes, including a nonintrusive inline mode in which the appliance functions as a network bridge with transparent TCP/IP packet forwarding.

Server-side solutions usually have a cheaper initial entry point, but as your Web services grow, maintaining consistent security standards and policies across all servers becomes increasingly difficult. Westbridge offers its XML Message Server (XMS) product both as server software that you can co-locate on the server that hosts your Web service and in the company's XA2500 Security and Management Appliance. Quadrasis's Quadrasis/Xtradyne SOAP Content Inspector is an application-layer security gateway whose strong suit is support for SAML. Flamenco Networks' Flamenco WSM is a Web services management and firewall solution that consists of a controller and multiple proxies and is available as a managed service as well as licensed software. An interesting variation on a software-based SOAP/XML firewall is Vordel's VordelSecure 2.0, which you can deploy either as a standalone firewall on a Windows, Sun Microsystems' Solaris, or Linux server or by deploying agents on firewalls and Web servers throughout your organization.

For large implementations, appliances are less costly to maintain and give you better manageability by providing a centralized view of your Web services network and its policies and activity. However, appliances must support all the standards and technologies that your combined Web services require. When you shop for a SOAP/XML firewall, whether it's implemented as an appliance or as software, be sure you evaluate standards support. You should familiarize yourself with the current and emerging standards in the Web services sector and identify those that your organization is most likely to need. Before you buy, make sure the product that you want supports those technologies. Table 1 lists common Web services standards.

Getting Ready
Sooner or later, Web services are coming your way, and you need to prepare your security infrastructure for their arrival. When you're ready to get a SOAP/XML firewall, you'll find the market crowded with a variety of offerings. As you sift through them, look for strong standards compliance and support for the Web services technologies that your organization uses (e.g., Framework, IBM's WebSphere platform, BEA Systems' BEA WebLogic Server) as well as support for management tools you use (e.g., IBM Tivoli, Microsoft Operations Manager—MOM). Finally, make sure the product you're considering provides the scalability you need.



Contact the Vendors
FIREWALL-1
Check Point Software Technologies * 650-628-2000
http://www.checkpoint.com

FLAMENCO WSM
Flamenco Networks * 678-990-4700
http://www.flamenconetworks.com

FORUM SENTRY 1500
Forum Systems * 781-788-4213 or 866-333-0210
http://www.forumsys.com

QUADRASIS/XTRADYNE SOAP CONTENT
INSPECTOR
Quadrasis * 781-768-5877 or 888-569-3803
http://www.hi.com

REACTIVITY XML FIREWALL
Reactivity * 650-551-7800 * http://www.reactivity.com

VORDELSECURE 2.0
Vordel * 617-536-6866 * http://www.vordel.com

WESTBRIDGE XA2500 SECURITY AND
MANAGEMENT APPLIANCE, XML
MESSAGE SERVER (XMS)

Westbridge Technology * 650-210-0700
http://www.westbridgetech.com

XS40 XML SECURITY GATEWAY
DataPower Technology * 617-864-0455
http://www.datapower.com


End of Article

   Previous  1  2  [3]  Next  


Reader Comments
I think a company named Tablus has a similar product functions as a outbound firewall which analyzes the streams for text.

Jim September 03, 2003


SOAP/XML is computation intensive, so hardware solution is the way to go.

Roboo November 06, 2003


Two solutions for XML/SOAP Security: gateway or plug-in agents.

Roboo December 09, 2003


I think MeshFire software plus hardware hybrid solution is more flexible. Small company and large enterprise have different requirements. Besides, SOAP XML is not in mainstream yet. Currently HTML is still the most traffic in the Web and internet.

Anonymous User December 04, 2004 (Article Rating: )


MeshFire grid firewall appliance or software, has scalability that single-point external gateway firewalls cannot match. This is their strength, I think. Actually their name implies security grid SecGrid, or grid security GridSec.

Anonymous User December 09, 2004


What algorithms do MeshFire use and work better than other alternatives for security risk detection and prevention in Web applications and SOAP/XML Web services? Can you stop viruses worms? hackers?

Anonymous User December 16, 2004


But does SOAP/XML web services security market ready? To me the adoption rate for web services are slow, at least not as rapid as it was expected a few years ago. So Meshfire or whatever company should better focus on the web application security market, in my opinion.

Anonymous User December 22, 2004 (Article Rating: )


I think soap xml web services are a black box providing services, you still need security and management for the overall infrastructure, so web application firewall, soap xml firewall and grid firewall are all needed.

Anonymous User December 31, 2004


I like the idea of MeshOS - the OS Operating System to control and manage the whole grid protected by MeshFire. It has been a headache to manage so many servers in our data center. MeshLog is also good for diagnostics when problems occur. I hope you have two MeshLog, for for short-term repository (1-2 months) and the other for long-term (1/2 - 1 year). Banks may need longer time for archiving of log files due to regulatory policy rules.

Anonymous User January 11, 2005


actually meshfire the first grid firewall has other modules or servers like MeshLog, MeshManager, MeshView, besides MeshOS. These are for log aggregation/correlation analysis, control and management, GUI reporting visualization, and fundamental support of Mesh large-scale distributed Web applications and services, including Web servers, application servers, and database servers.

Anonymous User January 12, 2005


 See More Comments  1   2   3   4   5 

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Windows 7 Sets Sales Record

Microsoft CEO Steve Ballmer described Windows 7's first ten days of sales as "fantastic" while in Japan yesterday. ...


Active Directory (AD) Whitepapers Meeting Compliance Objectives in SharePoint

Email Controls and Regulatory Compliance

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

DevConnections, Microsoft® ASP.NET Connections, SharePoint Connections and SQL Server Connections

Check out our list of Free Email Newsletters!

Active Directory (AD) eBooks The Essentials Series: Active Directory 2008 Operations

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement