Cloud Managed Networks

last person joined: 2 days ago 

Forum to discuss all things related to HPE Aruba Networking Central and UXI Network Management, including deployment of managed networks, configuration, best practices, APIs, Cloud Guest, AIOps, Presence Analytics, and other included Applications
Expand all | Collapse all

Removal of physical firewall for what?

This thread has been viewed 0 times
  • 1.  Removal of physical firewall for what?

    Posted Feb 11, 2020 02:38 PM

    Hi all

     

    In an Aruba central deployment with bgw and IAP and Aruba switched what is the beer method of firewall to deploy?

     

    I know central can come with pef license for application firewall but has anyone also deployed with the likes of Palo alto prisma or zscaler cloud based firewalls? Are these as effective as a physical firewall device ?

     

    Thanks



  • 2.  RE: Removal of physical firewall for what?

    EMPLOYEE
    Posted Feb 12, 2020 03:41 AM

    Actually, when you deploy an Aruba BGW, you get a full stateful L7 firewall in the same box at no additional cost than the gateway subscription

     

    https://help.central.arubanetworks.com/latest/documentation/online_help/content/gateways/cfg/security/applcation/app-visibility-ctrl.htm

     

    That also includes capabilities like Web Content (WebCC) and Geo Location filtering.

     

    Cloud Security providers like Zscaler or Palo Alto with Prisma have certainly some advanced threat detection/protection capabilities, that a single box can't deliver. The downside is, that for inspection you usually need to redirect traffic to their cloud service and back (reverse path pinning) which can incur delays for a client.

     

    We have simplified these integrations, that you can easily use them alongside the native firewall capabilities of the Aruba BGW

     

    Have a look at these:

     

    https://help.central.arubanetworks.com/latest/documentation/online_help/content/gateways/cfg/security/cloud-security/zscaler_integration.htm

     

    https://help.central.arubanetworks.com/latest/documentation/online_help/content/gateways/cfg/security/cloud-security/pan_cloud_integration.htm