I was searching the web in order to find out more about UTM firewalls and how to use them, when I bumped into
something that allowed me to get a better view
on how these things work. So, after reading what NetworkWorld had to say about this, here are a few tips on how to deploy these babies.
The first thing to do is to properly manage your firewall. Don't use a single system, but distribute firewall functionality. Let's just take a look at things - in a huge corporation there are many departments and they have different privileges when regarding Internet policy. The more policies the more complicated things get, so instead of buying a single super-powered UTM, try to distribute the burden.
The second important thing you can do is be careful when you check certain boxes. This is very important when talking about performance, one check in the wrong box could drop speed of 75% to 90% so, please be careful when you configure it.
The third thing is... well...don't be a cheapskate! Get a server with a huge hard drive and keep traffic records, not for yesterday, not for last week, but for years. This is very important. Traffic monitoring helps you figure out where attacks come from.
The fourth idea is to make sure that your firewall offers high availability and scalability. It is also good to test them with fake attacks and fake outages so that you may see what flaws you've got and what your vulnerabilities are.
The fifth thing to keep in mind is the fact that some UTMs will act like older versions of Windows - sometimes they're unreliable. So, after implementing new measures, check that they work properly and that they act the way you wanted them to.