Most small and mid-sized orgs probably lack the billion-dollar budget and manpower necessary to run a dozen different security tools each with their own console, licensing agreement, and learning monetary outlay. Unified threat management (UTM) appeared specifically to address this issue, bringing together some or all of firewall, IDS/IPS, antivirus/malware detection and prevention (AV), content filtering, and a virtual private network (VPN) function in a single appliance or platform that is manageable by smaller IT teams. The method gives up elements of the specialization found in best-of-breed point solutions to obtain simplicity, a combined view and a lower total cost of ownership.
The five providers that we detail below all offer slightly different flavors of this type of combined protection, from purpose-built hardware appliances to software platforms that are intended to run on infrastructure the customer already owns. By understanding these differences, organizations can narrow their search before making a request for a formal demo or quote from any specific vendor.
If you’re comparing options, cybersecurity solutions with integrated management can help you understand how a combined security platform implements unified threat management for expanding networks.
What Unified Threat Management REALLY Brings Together
A real UTM Platform will combine multiple security functions typically provided by standalone appliances. The heart of it is a firewall and intrusion prevention that filters and inspects traffic as it traverses the network perimeter. Antivirus and anti-malware scanning provide a second line of defense for stopping threats that are able to bypass perimeter controls; content filtering and application control gives administrators insight into what users are accessing and doing with the resources on the network.
VPN support completes the picture for most UTM suites and lets remote users and branch offices securely connect in without needing an additional dedicated VPN appliance. The real value of this consolidation increases with size, as managing dozens of branch locations is much better supported by a single, centralized managed platform than by many disconnected devices sitting at various sites where each location needs to keep track of updates and policies. Licensing structure also has meaningful variation among vendors: Some bundle everything in one subscription, while other only charge per module, a factor that can have an outsized impact on total cost of ownership during the lifetime of the solution.
Fortinet
Fortinet established credit with the integrated security appliance market that combines Firewall, Intrusion prevention and other layer 7 protections into a single architecture for centralized management across distributed environments. The platform takes a purpose-built hardware-acceleration approach, which is important for organizations that have found some competing UTM products slow down significantly as more inspection features are enabled.
SonicWall
SonicWall has been targeting the small and mid-sized business (SMB) market for years, with UTM appliances built for IT teams that don’t have dedicated security specialists on staff. Its portfolio covers a wide variety of appliance sizes, designed to scale from small branch offices to larger distributed enterprises, and centralized management suites that allow administrators to manage numerous locations as easily as a single location.
WatchGuard Technologies
WatchGuard Technologies focuses its UTM appliances on easy setup and a subscription model that bundles security services to appeal to organizations seeking predictable costs without the hassle of negotiating licenses for each capability. The platform supports tools with centralized visibility, designed to help smaller IT teams better understand what is happening across their network without requiring deep security expertise to derive intelligence from the data.
Untangle
Untangle gives you a software-centric offering based on unified threat management, going as far as giving you one product that can run on different hardware in comparison to other options out there because they don’t force any kind of proprietary appliance purchase. That flexibility has led to its popularity among smaller organizations and managed service providers seeking a lower-cost alternative that still meets the core functions expected of a UTM platform.
Netgate
Netgate is based on the open-source pfSense platform and will appeal to organizations seeking greater specificity in their firewall and UTM configurations than some fully managed appliances might offer. Those elements have led to a large community of users, thanks in part to the open architecture and ability to customize/extend the platform, although it does take considerable technical expertise relative to some more turnkey offerings in this list.
Firewall Standards: Something You Should Know Before Purchasing
It is important to first understand the foundational technology categories that power each UTM platform before one starts evaluating specific vendors. Some government documents, long since available, provide a valuable technical underpinning here. Organizations can be informed on best practices for firewall policy that describe packet filtering, stateful inspection and application layer firewalls as well as guidelines to help choose and implement the right type of firewall in a specific environment.
Building security around more than just the firewall
A UTM platform is a single building block in a larger network security strategy, and any vendor should be evaluated as part of that larger picture, as the firewall is not an entire solution in itself. Independent guidance on network security design guidance addresses other aspects that may need to be considered together with any UTM deployment, from network segmentation and secure remote access to ongoing monitoring, something which the organization should factor into its evaluative exercises regardless of which vendor selection ultimately ensues.
The choice among these five providers essentially boils down to which platform best aligns with your organizational scale and technical resources, with the deciding factor being between prioritizing raw performance, predictable subscription pricing, deployment flexibility, or granular configuration control. Platforms that put a premium on immutable infrastructure and can manage multiple accounts are typically better for organizations with limited internal IT staff, while organizations that make it work better when they have dedicated technical resources prefer more control over the amplitude offered through open portals.
Frequently Asked Questions
What is the benefit of unified threat management as opposed to using separate security tools?
UTM, short for Unified Threat Management, is more efficient than a large stack of services because it bundles many security features into one product, which enables you to avoid the hassle associated with overseeing disparate tools, licenses and consoles. This is particularly useful for organizations that do not have a large security team dedicated.
Are UTM Platforms or Firewalls right for big business?
UTM started as an SMB solution, but today most platforms scale to allow larger deployed networks with centralized management over much more network sites. More mature organizations ought to assess performance under heavier scrutiny workloads very carefully.
UTM vendors comparison: what organizations should consider first?
Performance under load, centralized management benefits (both ease of use and any licensing cost savings), price points, and how tightly all the security functions are bundled in each suite. The correct answer is strongly based on the scale of your network, technical skills in-house and budget allocation.
