TippingPoint announced their Core Controller appliance today. It is a 10GBPS in line IPS. Actually what it sounds like it is, is a network controller that load balances traffic among several conventional Tipping Point boxes and than puts the flow back together and passes it on. Sounds cool, but I would like to see the latency involved in doing this. Sounds like a lot of moving parts. It also sounds a lot like the way Hoff used to do things over at Crossbeam Systems.
The real question for me though is not whether or not this new appliance does line speed IPS or not. The question is do we still want our IPS as stand alone IPS or do we want it as part of UTM. Mike Rothman in his 2008 Days of Incite talks about "best of breed DOA". In it Mike talks about 2007 being a year where customers clearly voted for integrated solutions over individual best-of-breed. He also says 2007 was the year the first open source perimeter platforms hit. I like to think he is talking about Cobia. But 2008 will be an even bigger year for Cobia functionality! The bottom line though is except for the Ferrari crowd does anyone want to buy a stand alone IPS? Mike says it best when he says. "Market maturity kills product innovation".
Yes people buy UTM for one application at first. It could be firewall, it could be IPS or gateway AV, URL filtering or anti-spam. But they like the idea of getting more than what they just needed and paid for. They figure they are going to turn on the other stuff soon enough anyway. Plus they get it all from one vender. So on this one, I have to agree with Mike. I think people will buy UTM over single purpose security solutions in increasingly greater numbers in the months to come. Agree? Disagree? Leave a comment with your opinion.





