Skip to content
Notifications
Clear all

Hot take: If you aren't using AppSecure, you're only using half the firewall.

6 Posts
6 Users
0 Reactions
12 Views
(@crmsurfer_42)
Reputable Member
Joined: 4 months ago
Posts: 201
Topic starter   [#4563]

I saw this headline on a Juniper blog and it got me thinking. I'm new to SRX and mostly set up basic policies for web traffic.

Can someone explain what I'm missing without AppSecure? Like a concrete example of a threat it would catch that a standard policy wouldn't. Is it mostly for apps like Skype or Dropbox?

I'm trying to understand if it's a "nice to have" or a core security layer. My current firewall knowledge is pretty basic—block by port/IP.


Trying to figure it out.


   
Quote
(@charlotte0)
Reputable Member
Joined: 3 months ago
Posts: 241
 

That's a good starting point. Since you're working with port/IP based rules, think about something like HTTPS. You're allowing traffic on port 443 for web browsing.

AppSecure can identify the specific application running on that port. A user could be accessing a legitimate web service, or they could be running a file transfer service like Dropbox over that same HTTPS port. Your basic policy sees both as identical 'HTTPS on 443' and allows it.

The threat it catches is the unauthorized application you didn't intend to permit. It's not just about Skype or Dropbox. It's about any application that can tunnel over a standard, allowed port, which makes traditional blocking rules blind to it.

So it moves you from securing ports to actually controlling what people can do. Would you consider that a core layer?



   
ReplyQuote
(@finops_auditor_ray)
Honorable Member
Joined: 6 months ago
Posts: 467
 

You're describing the marketing benefit. Have you checked the CPU impact on your SRX with AppSecure turned on?

That "application identification" doesn't run for free. I've seen boxes hit 80%+ utilization because someone turned on every app-id and UTM feature without sizing for it. Suddenly your firewall becomes the bottleneck.

It's a core layer only if your hardware can handle it. Otherwise, you just bought an expensive choke point. What model SRX are we talking about here?


show me the bill


   
ReplyQuote
(@martech_intern)
Eminent Member
Joined: 4 months ago
Posts: 24
 

So if you're only blocking by port, what happens when someone runs a malicious app on port 80 or 443? It just looks like web traffic to the firewall. I think AppSecure would actually see what the app is.

Would that be right? I'm still learning too.



   
ReplyQuote
(@andrew8)
Reputable Member
Joined: 3 months ago
Posts: 365
 

Correct. Basic rules see traffic, AppSecure sees behavior.

But it's not magic. AppSecure uses signatures. A custom or unknown malicious app on port 443 might still look like generic SSL/TLS and get through. It's excellent for blocking known unauthorized apps tunneling over allowed ports, not a silver bullet for zero-days.

CPU overhead is the real catch, as user389 pointed out.


Numbers don't lie.


   
ReplyQuote
(@brian)
Reputable Member
Joined: 3 months ago
Posts: 282
 

You're missing unauthorized apps disguised as allowed traffic.

A user could run an FTP server over port 443, and your basic policy just sees HTTPS and lets it through. AppSecure can flag it as FTP and block it. That's the gap.

But calling it "half a firewall" is pure marketing. It's a feature, not the core.


Trust but verify.


   
ReplyQuote