Fortinet says it’s all about the security ASICs
- Reference: 1646950862
- News link: https://www.theregister.co.uk/2022/03/10/fortinet_security_asics/
- Source link:
"On day one, 22 years ago, we leveraged ASIC technology to lower computing costs, increase computing power, and also add additional performance and more function," Xie said, speaking at the Morgan Stanley Technology, Media and Telecom conference this week.
Using its custom ASICs to accelerate security and networking tasks lowers customers' security computing costs by as much as 10x compared to using CPUs, he claimed. This becomes even more important as multi-cloud, 5G with 6G on the horizon, and the convergence of IT and operational technology environments expand, while an onslaught of traffic from applications, users, and devices put greater demands on network equipment and defenses.
[1]
"The old technology cannot meet all the demand," Xie [2]argued .
[3]
[4]
Unlike some traditional switches and routers that can't determine context of an application, user, or device, Fortinet's internal segmentation is context aware, he added. "So that's where the ASIC basically does the same as like the GPU, TPU or IPU," Xie said.
This technology segments network and infrastructure assets across multiple clouds and in on-premises data centers, which Xie said better protects customers from ransomware and other threats that spread laterally through networks. Fortinet is not the only designer of network silicon, we must note: it is a competitor within a wide landscape of specialist processing units, including [5]latest-gen FPGAs and [6]accelerators attached to host servers.
[7]
Essentially, these kinds of chips offload the work of filtering network packets and applying policies from a general-purpose processor, and handle it in dedicated hardware. This can mean more throughput for routing and checking incoming, internal, and outgoing traffic, for one thing.
"If you want to have this zero-trust environment, you have to have network security go inside the company, go inside the data center to handle both the north-south traffic and east-west traffic," Xie continued. "The need is all there. And it all depends on who can solve this issue, increase the speed, because there's almost like a one-to-100 gap."
[8]Nvidia says its SmartNICs sizzled to world record storage schlepping status
[9]SmartNICs, IPUs, DPUs de-hyped: Why and how cloud giants are offloading work from server CPUs
[10]HPE's Aruba adopts DPUs, but in a switch, not a server
[11]Fortinet's security appliances hit by remote code execution vulnerability
Fortinet has a 40 percent market share in the network security space, according to Xie. That's larger than its next five closest competitors' shares combined, he claimed. "Last year the whole product revenue grew 47 percent," he said. "And the last quarter, the booking of the product probably grew over 60 percent."
Looking ahead to the rest of the year and beyond, Xie said he expects this network and security convergence to continue to boost Fortinet's growth.
He cited Gartner and IDC's cloud security market forecasts, and put that market at $20bn over the next four or five years.
[12]
"The network security is still two-times to three-times larger, and still a more healthy growth," he said. "Then, if we see the convergence of network and security, for us the total addressable market will be almost $200bn." ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YiqDF9icJMGoRiNJcyu@vAAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://seekingalpha.com/article/4494249-fortinet-inc-ftnt-ceo-ken-xie-presents-morgan-stanley-technology-media-and-telecom-conference
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiqDF9icJMGoRiNJcyu@vAAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiqDF9icJMGoRiNJcyu@vAAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2020/04/16/xilinx_versal_acap_samsung_5g_gear/
[6] https://www.theregister.com/2020/09/25/smartnic_dpu/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiqDF9icJMGoRiNJcyu@vAAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/12/22/nvidia_bluefield_storage_benchmark/
[9] https://www.theregister.com/2021/11/24/infrastructure_processing_units/
[10] https://www.theregister.com/2021/10/19/aruba_puts_dpus_in_a_switch/
[11] https://www.theregister.com/2021/07/20/fortinet_rce/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiqDF9icJMGoRiNJcyu@vAAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Interesting
I remember a similar pitch from Alteon. Remember them? Great technology, had a few bugs but was a great packet mangling ASIC.
Then Nortel bought them. Remember them?
Bollocks (ish)
I've deployed quite a few Fortinets and other firewalls/routers/packet ticklers. You need to be able to define your policy wrt internets and then you need to be able to deploy and enforce that policy. Everything else is stamp collecting!
Define your policy: Errr keep the baddies out and my users safe or somethink. OK this needs some work but out of the box you do get a reasonable set of defaults - bugger all with no indication of what to turn on. NAT enabled on all allow rules and other travesties.
Deploy it: Let's take a simple operation - allow access from the outside to a box on the inside. Oh $DEITY. Define a NAT policy (it isn't called that) in one place and then reference that in firewall rules. There are other methods too from the GUI or CLI that barely hide the underlying OS primitives.
What about a site to site VPN? That'll be IPSEC only thank you. Curve 25519 support has recently been added which is nice but the GUI is awful to navigate, its dreadfully clunky. Yes there's a CLI but it is yet another language to learn and I can't be arsed. FFS I already have to speak so many IT wanky languages already - most of them with a rubbish accent.
Fortinets may have loads of clever shit in the box but the GUI is wank for many of the basics. That goes for pretty much everything "cool" in IT these days. Lots of clever stuff with a crappy interface and half thought out interactivity. Support via whispers and innuendo on Reddit and shitty "forums".
Despite my whining, I won't go back to IT in the (say) noughties. What we have now is (mostly) rather better by an order of magnitude.
I do recommend you use the colour coding, even if it is a bit inconsistent. It does help make rule sets readable.