UTM vs NGFW: What Is the Difference?
UTM and NGFW began as two different ideas. Today the products have merged, and the terms tell you more about a vendor's marketing than about what the box does.
What UTM meant
Unified threat management appeared in the mid-2000s for small and mid-size businesses. It put a firewall, antivirus, web filtering, intrusion prevention and VPN in one box, so that a small office did not need five products. The trade-off was speed: switching everything on slowed early units badly.
What NGFW meant
The next-generation firewall came from the enterprise side. Its defining idea was to identify the application and the user behind traffic, not only the port number, and to write rules in those terms: allow this team to use that application.
Where they stand today
Every firewall on this site does both. Small-office models identify applications and users, and large ones include web filtering and anti-malware. The practical differences are now in performance, in how the rules are managed, and in what the licence includes.
What to ask for
- Application and user identification in the rules
- Intrusion prevention and anti-malware, with the throughput measured while they are on
- Web filtering by category
- Inspection of encrypted traffic, and the throughput figure for it
- Central management, if you have more than one site
Common questions
Is a UTM firewall less secure than an NGFW?
Not by the label. Compare what each one inspects and how fast it does so with those features on.
Do I need an NGFW for a small office?
You need a firewall that inspects traffic and identifies applications, which every current business model does. The name on the box matters less than keeping its licence and firmware current.
What is a next-generation firewall in one sentence?
A firewall that decides what to allow by looking at the application, the user and the content, not only the address and port.