<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Why Network Appliances Suck and What to Do About It</title>
	<atom:link href="http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/</link>
	<description>Network Security News, Analysis and Ephemera</description>
	<lastBuildDate>Tue, 27 Jul 2010 05:54:52 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Brian</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-1475</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Fri, 23 Oct 2009 16:45:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-1475</guid>
		<description>&lt;p&gt;I like the package OS and software services in ISO distro from IPCOP. Open source and installable to most hardware platforms.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I like the package OS and software services in ISO distro from IPCOP. Open source and installable to most hardware platforms.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Robinson</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-17</link>
		<dc:creator>Jon Robinson</dc:creator>
		<pubDate>Wed, 21 Mar 2007 15:11:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-17</guid>
		<description>&lt;p&gt;@Rob-Thank you.  I got my degree in electrical engineering, so my mind operates slightly differently than a typical sales guy.  I also don&#039;t have a quota or a manager, and I think that is half the reason sales people behave the way they do!&lt;/p&gt;

&lt;p&gt;@Mitchell-Thank you for the complimentary post.  I am glad to hear that you plan to make everthing open.  In that case, I&#039;m positive that UNP will be the best option for many.  &lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Rob-Thank you.  I got my degree in electrical engineering, so my mind operates slightly differently than a typical sales guy.  I also don&#8217;t have a quota or a manager, and I think that is half the reason sales people behave the way they do!</p>

<p>@Mitchell-Thank you for the complimentary post.  I am glad to hear that you plan to make everthing open.  In that case, I&#8217;m positive that UNP will be the best option for many.  </p>]]></content:encoded>
	</item>
	<item>
		<title>By: Mitchell Ashley</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-16</link>
		<dc:creator>Mitchell Ashley</dc:creator>
		<pubDate>Wed, 21 Mar 2007 13:25:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-16</guid>
		<description>&lt;p&gt;All - great conversation here and thanks to you Jon for sparking the discussion.&lt;/p&gt;

&lt;p&gt;A couple of things about UNP; one of the areas I&#039;m working to innovate in is to create an open platform where essentially everything is open, including the platform as well as modules that ride along on top of it.&lt;/p&gt;

&lt;p&gt;In my mind, that&#039;s the best of all worlds; create an appliance-like environment but instead of an appliance the vendor puts together (software choices, and hardware), you the user can take the UNP as the starting point and if you chose to you can then fully customize it with other modules,  or even create your own security and network functions. Additionally, if you as a security professional don&#039;t like something in how the platform is constructed then that would open for customization as well.&lt;/p&gt;

&lt;p&gt;Here&#039;s an interesting idea; make the UNP available in some form of open source. Now anyone can innovate  with UNP and completely craft their own environment or make technology that others can use, and create new modules that can be shared with others.&lt;/p&gt;

&lt;p&gt;Also, regarding the comparison with Crossbeam, I think Rory said it well. Crossbeam has an excellent platform for operating 3rd party products on some attractive hardware. Chris Hoff, a good friend of mine, has done an excellent job with Crossbeam&#039;s architecture and approach. One thing to note is that they focus on carrier and high end enterprise markets. Here&#039;s a thought; UNP could actually be a good complement to what they are doing.&lt;/p&gt;

&lt;p&gt;Thanks for the conversation all. If you like, check out some early work we are doing with UNP at &lt;a href=&quot;http://cobia.stillsecure.com.&quot; rel=&quot;nofollow&quot;&gt;http://cobia.stillsecure.com.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Also, Jon, I put up a post about your site;   &lt;a href=&quot;http://www.theconvergingnetwork.com/2007/03/jons_views_on_appliances_1.html&quot; rel=&quot;nofollow&quot;&gt;http://www.theconvergingnetwork.com/2007/03/jons&lt;em&gt;views&lt;/em&gt;on&lt;em&gt;appliances&lt;/em&gt;1.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Good work all. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Mitchell&lt;/li&gt;
&lt;/ul&gt;
</description>
		<content:encoded><![CDATA[<p>All &#8211; great conversation here and thanks to you Jon for sparking the discussion.</p>

<p>A couple of things about UNP; one of the areas I&#8217;m working to innovate in is to create an open platform where essentially everything is open, including the platform as well as modules that ride along on top of it.</p>

<p>In my mind, that&#8217;s the best of all worlds; create an appliance-like environment but instead of an appliance the vendor puts together (software choices, and hardware), you the user can take the UNP as the starting point and if you chose to you can then fully customize it with other modules,  or even create your own security and network functions. Additionally, if you as a security professional don&#8217;t like something in how the platform is constructed then that would open for customization as well.</p>

<p>Here&#8217;s an interesting idea; make the UNP available in some form of open source. Now anyone can innovate  with UNP and completely craft their own environment or make technology that others can use, and create new modules that can be shared with others.</p>

<p>Also, regarding the comparison with Crossbeam, I think Rory said it well. Crossbeam has an excellent platform for operating 3rd party products on some attractive hardware. Chris Hoff, a good friend of mine, has done an excellent job with Crossbeam&#8217;s architecture and approach. One thing to note is that they focus on carrier and high end enterprise markets. Here&#8217;s a thought; UNP could actually be a good complement to what they are doing.</p>

<p>Thanks for the conversation all. If you like, check out some early work we are doing with UNP at <a href="http://cobia.stillsecure.com." rel="nofollow"></a><a href="http://cobia.stillsecure.com" rel="nofollow">http://cobia.stillsecure.com</a>.</p>

<p>Also, Jon, I put up a post about your site;   <a href="http://www.theconvergingnetwork.com/2007/03/jons_views_on_appliances_1.html" rel="nofollow"></a><a href="http://www.theconvergingnetwork.com/2007/03/jons" rel="nofollow">http://www.theconvergingnetwork.com/2007/03/jons</a><em>views</em>on<em>appliances</em>1.html</p>

<p>Good work all. </p>

<ul>
<li>Mitchell</li>
</ul>]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Newby</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-15</link>
		<dc:creator>Rob Newby</dc:creator>
		<pubDate>Wed, 21 Mar 2007 11:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-15</guid>
		<description>&lt;p&gt;I&#039;m impressed. A lot sales guys I came across in the channel wouldn&#039;t have had the first clue about these ideas. &lt;/p&gt;

&lt;p&gt;What would be really nice is a standardised (SOA-based) compliance framework (open-source of course) that we could build on and just add very specific tools to address our various needs.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I&#8217;m impressed. A lot sales guys I came across in the channel wouldn&#8217;t have had the first clue about these ideas. </p>

<p>What would be really nice is a standardised (SOA-based) compliance framework (open-source of course) that we could build on and just add very specific tools to address our various needs.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Robinson</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-14</link>
		<dc:creator>Jon Robinson</dc:creator>
		<pubDate>Wed, 14 Mar 2007 23:08:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-14</guid>
		<description>&lt;p&gt;@Rob: I am in sales and the great thing about sales is that there will always be something to sell.  My goal is to solve problems.  Appliances do have advantages and do solve problems, obviously, but they have disadvantages that can be overcome if they had more extensibility and modularity.&lt;/p&gt;

&lt;p&gt;@Osama: I think that if you had a product where the feature sets were more like plug-ins then you wouldn&#039;t be as much at the mercy of a vendor.  You may be at the mercy of the framework that you chose, but adding, changing, and managing features would be a matter of buying or creating the appropriate plug-in for your needs.  You wouldn&#039;t have to swap out the entire solution for an incremental increase in the feature set.&lt;/p&gt;

&lt;p&gt;@Rory: &quot;There&#039;s one other element to appliances that always makes me worry somewhat, which is that you&#039;re at the mercy of the vendor for security patches.&quot;
Good Point.  &lt;/p&gt;

&lt;p&gt;&quot;whereas the stillsecure UNP product looks (again AFAICS) to be more shaping up as something they&#039;ll provide all the base modules for...&quot;&lt;/p&gt;

&lt;p&gt;I&#039;m wondering how this will shape up as well.  Hopefully anyone will be able to create a mod.  That would hopefully spark lots of innovation and advancement.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Rob: I am in sales and the great thing about sales is that there will always be something to sell.  My goal is to solve problems.  Appliances do have advantages and do solve problems, obviously, but they have disadvantages that can be overcome if they had more extensibility and modularity.</p>

<p>@Osama: I think that if you had a product where the feature sets were more like plug-ins then you wouldn&#8217;t be as much at the mercy of a vendor.  You may be at the mercy of the framework that you chose, but adding, changing, and managing features would be a matter of buying or creating the appropriate plug-in for your needs.  You wouldn&#8217;t have to swap out the entire solution for an incremental increase in the feature set.</p>

<p>@Rory: &#8220;There&#8217;s one other element to appliances that always makes me worry somewhat, which is that you&#8217;re at the mercy of the vendor for security patches.&#8221;
Good Point.  </p>

<p>&#8220;whereas the stillsecure UNP product looks (again AFAICS) to be more shaping up as something they&#8217;ll provide all the base modules for&#8230;&#8221;</p>

<p>I&#8217;m wondering how this will shape up as well.  Hopefully anyone will be able to create a mod.  That would hopefully spark lots of innovation and advancement.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rory McCune</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-13</link>
		<dc:creator>Rory McCune</dc:creator>
		<pubDate>Wed, 14 Mar 2007 20:59:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-13</guid>
		<description>&lt;p&gt;There&#039;s one other element to appliances that always makes me worry somewhat, which is that you&#039;re at the mercy of the vendor for security patches.  &lt;/p&gt;

&lt;p&gt;Fundamentally most of these appliances run some sort of Linux or BSD based OS and where there are security vulnerabilities in the bits of the OS that the vendor has installed (which end-users probably won&#039;t have a list of) you need the vendor to provide a patch...&lt;/p&gt;

&lt;p&gt;In terms of comparing Stillsecure Cobia with Crossbean I think that they&#039;re taking a slightly different approach maybe more in terms of scale than anything else.  &lt;/p&gt;

&lt;p&gt;Crossbeam (AFAICS) focuses on integrating existing security products like Checkpoint Firewalls, sourcefire IDS etc and putting them alltogether in a clever form-factor with some v. clever integration, whereas the stillsecure UNP product looks (again AFAICS) to be more shaping up as something they&#039;ll provide all the base modules for...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>There&#8217;s one other element to appliances that always makes me worry somewhat, which is that you&#8217;re at the mercy of the vendor for security patches.  </p>

<p>Fundamentally most of these appliances run some sort of Linux or BSD based OS and where there are security vulnerabilities in the bits of the OS that the vendor has installed (which end-users probably won&#8217;t have a list of) you need the vendor to provide a patch&#8230;</p>

<p>In terms of comparing Stillsecure Cobia with Crossbean I think that they&#8217;re taking a slightly different approach maybe more in terms of scale than anything else.  </p>

<p>Crossbeam (AFAICS) focuses on integrating existing security products like Checkpoint Firewalls, sourcefire IDS etc and putting them alltogether in a clever form-factor with some v. clever integration, whereas the stillsecure UNP product looks (again AFAICS) to be more shaping up as something they&#8217;ll provide all the base modules for&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Osama Salah</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-12</link>
		<dc:creator>Osama Salah</dc:creator>
		<pubDate>Wed, 14 Mar 2007 17:07:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-12</guid>
		<description>&lt;p&gt;&quot;1. The customer is at the mercy of the vendor when it comes to product development....&quot;&lt;/p&gt;

&lt;p&gt;Isn&#039;t that always the case? What other situation is there where you wouldn&#039;t be at the mercy of the vendor? Are you going to reverse engineer and patch products to your liking?&lt;/p&gt;

&lt;p&gt;&quot;Mitchell Ashley envisions a framework entitled the Unified Networking Platform.&quot;&lt;/p&gt;

&lt;p&gt;Sound close to what Crossbeam are doing. I suppose their platform is propretary, maybe UNP will be open.
Security products need to talk one common language, they need to be interfacable but no vendor seems to be interested, they prefer selling you their own modules and lock you down.&lt;/p&gt;

&lt;p&gt;Another apsect of appliances I don&#039;t like is that if they should break you are at the mercy of the reseller to provide a replacement unit which can take some time. With software you can just reinstall it on another server. In that regard solutions that come as ISO images and you can pretty much install on any hardware are pretty cool. Virtual machine images are also a neat solution in that regard.&lt;/p&gt;

&lt;p&gt;rgds
Osama Salah&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>&#8220;1. The customer is at the mercy of the vendor when it comes to product development&#8230;.&#8221;</p>

<p>Isn&#8217;t that always the case? What other situation is there where you wouldn&#8217;t be at the mercy of the vendor? Are you going to reverse engineer and patch products to your liking?</p>

<p>&#8220;Mitchell Ashley envisions a framework entitled the Unified Networking Platform.&#8221;</p>

<p>Sound close to what Crossbeam are doing. I suppose their platform is propretary, maybe UNP will be open.
Security products need to talk one common language, they need to be interfacable but no vendor seems to be interested, they prefer selling you their own modules and lock you down.</p>

<p>Another apsect of appliances I don&#8217;t like is that if they should break you are at the mercy of the reseller to provide a replacement unit which can take some time. With software you can just reinstall it on another server. In that regard solutions that come as ISO images and you can pretty much install on any hardware are pretty cool. Virtual machine images are also a neat solution in that regard.</p>

<p>rgds
Osama Salah</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Newby</title>
		<link>http://jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/comment-page-1/#comment-11</link>
		<dc:creator>Rob Newby</dc:creator>
		<pubDate>Wed, 14 Mar 2007 10:21:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonsnetwork.com/2007/03/why-network-appliances-suck-and-what-to-do-about-it/#comment-11</guid>
		<description>&lt;p&gt;Hi Jon, &lt;/p&gt;

&lt;p&gt;First off you&#039;re right to say that devices caught on from Cisco&#039;s mass production of routers and switches as dedicated machines to do a single job rather than the functionality being built into their UNIX hosts - as had happened up until then. &lt;/p&gt;

&lt;p&gt;Devices became popular because they addressed a business issue (way back in time), simple supply and demand. The reason devices are now lost is because they are seen as the easy way out. If you want to sell it, package it up and ship it out. They no longer address a business need, but we are trying to crowbar them in to our networks, whether we need them or not. &lt;/p&gt;

&lt;p&gt;However, I can&#039;t see why as a reseller you hate appliances. You get to pick and choose after all. You ARE the demand. &lt;/p&gt;

&lt;p&gt;Are you sales or a techie? If you&#039;re sales then you should be delighted at how much margin you can make on these things, the challenge of the sale is getting around the objections. You ARE the crowbar!&lt;/p&gt;

&lt;p&gt;If you&#039;re a techie, enjoy yourself! You&#039;ll learn (and earn) loads in the channel, and before you know it you&#039;ll end up at a vendor, realising why it&#039;s so hard in the first place!&lt;/p&gt;

&lt;p&gt;You are also correct to think that Mitchell Ashley has the right idea in pushing for a framework approach to IT. He is the smartest of cookies. We will be seeing a lot more in the open source SOA framework space in the coming months, vendors providing add on tools where neccessary. And as a vendor, I hope to be riding the new wave, not stuck at the end of the last one watching everyone else ride in to the beach.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi Jon, </p>

<p>First off you&#8217;re right to say that devices caught on from Cisco&#8217;s mass production of routers and switches as dedicated machines to do a single job rather than the functionality being built into their UNIX hosts &#8211; as had happened up until then. </p>

<p>Devices became popular because they addressed a business issue (way back in time), simple supply and demand. The reason devices are now lost is because they are seen as the easy way out. If you want to sell it, package it up and ship it out. They no longer address a business need, but we are trying to crowbar them in to our networks, whether we need them or not. </p>

<p>However, I can&#8217;t see why as a reseller you hate appliances. You get to pick and choose after all. You ARE the demand. </p>

<p>Are you sales or a techie? If you&#8217;re sales then you should be delighted at how much margin you can make on these things, the challenge of the sale is getting around the objections. You ARE the crowbar!</p>

<p>If you&#8217;re a techie, enjoy yourself! You&#8217;ll learn (and earn) loads in the channel, and before you know it you&#8217;ll end up at a vendor, realising why it&#8217;s so hard in the first place!</p>

<p>You are also correct to think that Mitchell Ashley has the right idea in pushing for a framework approach to IT. He is the smartest of cookies. We will be seeing a lot more in the open source SOA framework space in the coming months, vendors providing add on tools where neccessary. And as a vendor, I hope to be riding the new wave, not stuck at the end of the last one watching everyone else ride in to the beach.</p>]]></content:encoded>
	</item>
</channel>
</rss>
