View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
September 6, 2011

Palo Alto founder slams Sourcefire next gen firewall move

'Bullshit' move from company 'fighting for its life', says Nir Zuk

By Steve Evans

Nir Zuk, founder and CTO of Palo Alto Networks has slammed Sourcefire’s attempts to move into the next generation firewall (NGFW) market as ‘bullshit’ and without ‘a chance in hell’ of succeeding.

Nir Zuk, Palo Alto Networks
Nir Zuk, founder and CTO of Palo Alto Networks

Sourcefire, creator of the Snort intrusion prevention system (IPS), announced last year that it would be moving into the NGFW space alongside the likes of Palo Alto Networks and Barracuda.

Speaking to CBR earlier this year, Sourcefire founder Marty Roesch said: "There seems to be an opportunity around the NGFW space from a couple of different angles. If you look at some of the market predictions a fair amount of the IPS market will be delivered on NGFW markets and we don’t want to cede market."

"Also if you look at the vendors that are building NGFW almost all are coming at it from the firewall direction to build IPS, and we’ve already got the best IPS on the planet. We think building application control is not as difficult as building a world class IPS," he added.

However Nir Zuk, who worked at Check Point, NetScreen Technologies and OneSecure before starting Palo Alto Networks, told CBR that Sourcefire was taking the wrong approach, and that coming at the NGFW market from an IPS angle was not going to work.

Content from our partners
The hidden complexities of deploying AI in your business
When it comes to AI, remember not every problem is a nail
An evolving cybersecurity landscape calls for multi-layered defence strategies

"I think it’s complete bullshit," he said. "The idea that an IPS can be converted to a firewall is extremely silly to me. There is a reason why the IPS market is $1bn and the firewall market is $5bn; it’s because it’s much more difficult to build a firewall than it is to build an IPS."

"Firewalls are not about allowing or denying a packet. The difference between a firewall and IPS is that the firewall is part of the infrastructure whereas an IPS is a tool that just looks at the network and every now and then stops something," Zuk added.

Zuk suggested that Sourcefire’s move into the NGFW market was borne out of desperation.

"Nobody’s buying a standalone IPS anymore, especially with the economy," he said. "The standalone IPS companies are in trouble and Sourcefire is fighting for its life, and of course they will say they’re going to build the Next Generation Firewall but I don’t see a chance in hell that it will work for them."

"If it was simple to build a firewall you would have more firewall companies out there. There are more companies in that $1bn IPS industry than in the $5bn firewall industry, and there is a reason for that," he added.

Sourcefire declined CBR’s request for comment.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU