As many organizations migrate to the cloud, a common misconception is that the hyperscalers they are using put the appropriate security in place, Fortinet Consulting Cloud Architect John McDonough said during a vendor webinar, before pointing to Microsoft as a chief example.

“One of the things that people think about when they get to the cloud is, well, it's a cloud, it's secure. It's a big name company that I'm using, and they put security in place for me, but that isn't really the case.” McDonough said. “They've given you the building blocks perhaps, but you have to put it together.”

From a firewall perspective, McDonough said the options Microsoft offers for its Azure cloud provide some key capabilities, like intrusion detection systems (IDS), transport layer security (TLS), and Uniform Resource Locator filtering for web categories.

But the “immature” Azure firewall often requires add-ons for many capabilities to be activated, and its tools are “only okay” compared to solutions from pure-play security vendors, he added.

According to McDonough, intrusion prevention, botnet protection, SD-WAN support, data loss prevention (DLP), and virtual patching are among the other critical capabilities organizations should be looking for in a firewall product.

“Protect not just what's behind your firewall, but protect the things that are going to and from and the people that are connected to that firewall,” McDonough said. “So you need all these things, all these features in the cloud, to maintain that security posture.”

Application Awareness for a Fortified Firewall

Aiden Walden, senior director of consulting systems engineering at Fortinet, said one of the most critical considerations when choosing a firewall is Application awareness – which he noted goes beyond identifying an Application’s traffic stream and making security decisions.

Organizations need to understand not just the foundational components of an Application, but also the patterns that evolved over time with the use of that Application, Walden explained.

Layer-four firewall protection uses ports like Transmission Control Protocol ports to manage virtual connections between the host where the browser is running and the host where a Server Application is running. But Walden said for highly critical applications – like Enterprise resource planning (ERP) applications – security based on ports might not be enough.

McDonough added that because SAP has dynamic ports that are constantly changing, the Application “doesn't really work great with the Azure firewall.”

“[Microsoft] has a document on what to expect when you're using SAP with their firewall and how you may want to incorporate more utilization of network security groups,” he said. “This is how you would mitigate, I guess, the limitation of that product.”

A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources, according to Microsoft. For each rule, you can specify source and destination, port, and protocol.

McDonough said even though network security groups are a great foundation for a firewall, relying on them is like “carrying water in a basket, things leak through it.”

“I don't want to be insensitive to the immaturity of their product. But I do want to say that Application awareness is a big deal. What your users are accessing, where they're going, it's in both directions,” he added. “Certainly for protecting an Application like SAP, we want to make sure that our policies, our procedures, our capabilities are finally tunable to that particular Application.”

The SASE Relationship

Gartner’s term for the convergence of networking and security as a cloud-delivered service — secure access service edge (SASE) — includes security services edge (SSE), a cloud-delivered security suite that packs zero-trust network access (ZTNA), cloud-access security broker (Cloud Access Security Broker), secure web gateway (SWG), and firewall-as-a-service (FaaS).

Walden said organizations need to be thinking more broadly than just their choice of firewall, to their entire security fabric – and SASE can be that built-in security fabric.

He added SASE is a “great all-in-one solution,” but that whether the architecture is ideal depends on each organization’s specific needs. “If you're an organization that has a predilection toward consuming Software-as-a-Service services and you really want to not manage infrastructure, SASE is a great solution,” Walden said. SASE optimizes access to other SaaS services as a “complement to cloud environments.”

SASE can also encompass various remote-worker use cases with a “full-stack approach to security,” Walden noted.

“That's what SASE is meant to be, [it's] all encompassing. So I think SASE is a great solution and a great alternative if you are resource constrained within your security practice,” he said.