SlideShare a Scribd company logo
COMPETITIVE COMPARISON AND EVALUATION



       OpenDNS Enterprise vs. Web Proxies or Firewall Filters
       OpenDNS (step 1) delivers Internet-wide security and Web filtering leading competitive solutions,
       (step 2) which rely on lower performance, less effective Web proxy or firewall filter platforms.
       Replacing these traditional heavyweight solutions can significantly reduce on-going maintenance and secure Internet
       connections faster from every device on any number of networks, anywhere (compare the first two rows below).
       Alternatively, adding OpenDNS will extend protection to unmanaged devices or network locations where existing
       solutions are cost prohibitive, as well as reduce much of the unwanted heavyweight traffic from configured devices and
       networks clogging your existing solutions (compare the last two rows below).
                        LIGHTWEIGHT TRAFFIC                       STEP 1 STEP 2             HEAVYWEIGHT TRAFFIC

                                                                     OpenDNS
                  AUTHORITATIVE      SAFE, FAST, SMART,          ALL DEVICES, NO CLIENT        SECURE, FAST        TCP SERVERS
                  DNS SERVERS       RELIABLE RESPONSES           OR NETWORK CHANGES        INTERNET CONNECTIONS     AND SITES

                                                                                                NO LATENCY
                                                                                              NO BOTTLENECKS




                                                          Web Proxy or Firewall Filter
                  AUTHORITATIVE     NOT ALWAYS RELIABLE,      CLIENT SETTINGS/SOFTWARE    SOME SECURE, BUT SLOW,   TCP SERVERS
                  DNS SERVERS      CONSISTENT RESPONSES     OR NETWORK TOPOLOGY CHANGES    INTERNET CONNECTIONS     AND SITES


                                     1 OR MORE ISPs                                           PROXY     FILTER




                                              Web Proxy or Firewall Filter plus OpenDNS
                  AUTHORITATIVE      SAFE, FAST, SMART,           ALL DEVICES, PLUS         SECURE, FEWER SLOW,    TCP SERVERS
                  DNS SERVERS       RELIABLE RESPONSES          ANY EXISTING CHANGES       INTERNET CONNECTIONS     AND SITES


                                                                                              PROXY     FILTER




       OpenDNS protects every device, which supports Bring Your Own Device (BYOD) programs, and secures every Internet
       connection, via a user interface not bloated with unused, complex bells and whistles. Like Web proxies and firewall
       filters, OpenDNS filters inappropriate sites for compliance, yet can easily scale from 1 to 1000s of network locations.

         ! BENEFIT         SOLUTION "         OpenDNS In-the-cloud Web Proxies On-premises Web Proxies On-premises Firewall Filters

            Protect every on-net device
         without client or network changes      #                                          $
            Easy to manage without any
                                                                                           $
                                                                MANY REQUIRE NEW
         software or hardware to maintain       #         % ON-PREMISES TRAFFIC
                                                            TO REDIRECT
                                                                        DEVICES


         Secure any Internet connection –
          any application, protocol or port     #                                          $
           Filter inappropriate sites and
          grant overrides to select users       #
            Scale to 1000s of network
            locations cost-effectively          #                                          $
For more information please visit: www.opendns.com or call 877-811-2367
Many security vendors focus on its solutions’ efficacy to block threats,
but gloss over its usability or performance.

USABILITY                                     It is not uncommon for Web proxies and firewall filters to take days
Vendors often assume administrators are       to weeks before it is effectively enforcing devices and reporting
investing their time in addition to their     activity. Add on training to learn how to manage all the complex
organization’s money to use the solution,     bells and whistles, many which go unused, and on-going
so they do not focus on how easy it is to:    maintenance to address performance or efficacy issues, and the
                                              ownership cost increases. OpenDNS can enforce every device – on
     • provision and setup,                   any network – and report activity within an hour of asking for an
     • enforce and report,                    evaluation trial. Our simple Web-based management interface and
                                              issue-free operation, means you set and forget it.
     • manage and maintain.

PERFORMANCE                                   Often Web proxies and firewall filters are deployed within the
Also, vendors often offer cryptic or rather   network using a less redundant topology than if they never existed,
meaningless specifications regarding the      which can result in new points of failure. They add new hops for
product’s performance, which do not           Internet connections and/or processes applied to Internet traffic,
always accurately reflect its:                which can increase latency and decrease throughput; leading to less
                                              happy users. OpenDNS simply replaces a mandatory, already in-use
    • reliability and resiliency,             service provided by Internet Service Providers (ISP). Our Anycast and
    • connection speed, and                   SmartCache technologies enable faster, more reliable Internet
                                              connections relative to most ISPs, by reducing hops and processes.
    • bandwidth throughput.

EFFICACY                                      Web proxies, in particular, provide minimal network coverage
Finally, while vendors may claim they have    depending on the setup of managed devices or networks. Often
superior threat intelligence and              only traffic sent by configured browsers is protected; not Web-
prevention, consider more completely its:     based outbound botnet traffic from infected devices’ malicious
                                              software. The Web may be the most used protocol, but it is one
     • network coverage,                      amongst hundreds that threats utilize and proxies are blind to.
     • threat coverage,                       Firewalls often only filter by destination for Web traffic; some using
                                              a built-in Web proxy. Firewalls filtering other protocol or application
     • accuracy and                           traffic often do not distinguish between good or bad destinations
       timeliness.                            for this traffic. OpenDNS ensures that malware, phishing,
                                              inappropriate sites and botnets never touch your network,
                                              regardless of application, protocol, port or device. OpenDNS
                                              maximizes the return on your security investments.
                              PE
         TY




                                RF
        ILI




                                  OR
     AB




                  LOW TCO,
                                    MA




                                              The evaluation matrix on the following page provides
   US




                  HIGH ROI,
                                       N




                                              more detail on how OpenDNS’s in-the-cloud solution
                                        CE




                   HAPPY
                   USERS                      compares to Web proxies – delivered in-the-cloud or on-
                                              premises – or on-premises firewall filters. We believe that
                                              you will draw the same conclusions, that OpenDNS
                 EFFICACY                     delivers a more usable, high performance and effective
                                              solution than competitors’ traditional solutions.
SOLUTION           OPENDNS                        WEB PROXIES                                                 FIREWALL FILTERS
   Delivery
                   • In-the-cloud                 • In-the-cloud                • On-premises                 • On-premises
   Platform
USABILITY
                   • Lightweight DNS query                                      • Receive and deploy          • Receive and deploy
                                               • Heavyweight TCP traffic
                     redirection without                                          appliance per site            appliance per site
                                                 redirection per site
                     network topology changes                                   • Heavyweight TCP traffic     • Significant configuration
   Provision                                   • Requires network
                     for 1 to 1000s of sites                                      redirection per site          to control network traffic
   & Setup         • No appliances or client
                                                 topology change, client
                                                                                • Requires network              flow is likely required to
                                                 software or setting
                     software                                                     topology change, client       migrate from current
                                                 changes
                   • No client setting changes                                    software or changes           firewall

                   • Network-level granularity • User-level granularity via                              • Network-level granularity
                                                                            • User-level granularity via
                     via public IP               directory integration                                     via internal IP
                                                                              directory integration
   Enforce         • Grant override              requires complex setup or                               • User-level granularity
                                                                              requires complex setup
   & Report          permissions to users        network-level granularity                                 requires complex setup
                                                                            • Data retention limited by
                   • Full data retention for 2 • Data retention often                                    • Data retention limited by
                                                                              internal storage available
                     years with no hidden fees   limited or else extra fees                                internal storage available
                   • Simple set and forget        • Often security rules are    • OS patch conflicts or     • Complex and focused on
                   • No OS patches or               complex, and require          upgrade downtime            network management, not
                     appliance upgrades             fine-tuning to reduce       • Often security rules are    policy or security, so it is
  Manage &
                   • No security rule tuning        false positives/negatives     complex and require fine-   often confusing
  Maintain                                        • SSL or auth. issues           tuning                    • If SSL or auth. is
                   • No site exceptions to
                     address SSL decryption         require frequent site       • SSL or auth. issues         included, then issues will
                     or authentication issues       exceptions                    require site exceptions     require site exceptions
PERFORMANCE
                   • No outages since launch      • Many have had outages       • Often reduced network     • Sometimes reduced
 Reliability &
                     in 2006                        despite SLA                   redundancy in topology or   network redundancy in
  Resiliency       • Uses Anycast IPs             • Lack Anycast IPs              else expensive              topology

                   • No new latency                                          • Adds new latency due to • May add new latency
                   • Often reduced response       • Adds new latency due to    another intermediate hop  depending on internal
  Connection
                     time via SmartCache            one or more intermediate • Spikes in traffic will    processes and the
    Speed          • Spikes in traffic will not     hops                       cause noticeably slower   number of add-on
                     cause slower speeds                                       speeds                    features enabled

                   • Virtually unlimited via      • Likely unlimited, but      • Limited by resources       • Limited by resources
  Bandwidth
                     lightweight queries &          heavyweight traffic          available on appliance or    available on appliance or
  Throughput         responses                      redirection can be limited   server; often a bottleneck   server
EFFICACY
                                                 • Depending on setup, only • Depending on setup, only • Any on-net device;
                   • Any on-net device;            managed devices and           managed devices and           managed or not
                     managed or not                configured browser            configured browser          • Filters by destination over
   Network
                   • Filters by destination over   applications                  applications                  HTTP/S, 80/443
   Coverage          any application, any        • Filters by destination over • Filters by destination over • May include protocol or
                     protocol and any port         only HTTP/S and ports         only HTTP/S and ports         application filters, but
                                                   80/443                        80/443                        not by destination

                   • Industry-leading             • Ineffective outbound        • Ineffective outbound
                     outbound botnet                protection due to             protection due to           • Outbound protection
                     protection                     inadequate network            inadequate network            usually not a focus
    Threat         • Inbound malware and            coverage                      coverage                    • Inbound protection is
   Coverage          phishing protection          • Inbound protection use      • Inbound protection use        usually via 3rd-parties so
                   • Web filtering categories       proprietary and/or 3rd-       proprietary and/or 3rd-       efficacy is not controlled
                     for regulatory & AUP           party systems                 party systems               • On-par Web filtering
                     compliance                   • On-par Web filtering        • On-par Web filtering
                   • Proactive protection is                                                                  • Not usually a core focus
  Accuracy &                                      • Often need to fine-tune     • Often need to fine-tune
                     updated 24x7 via                                                                           of business or products,
                                                    security rules to prevent     security rules to prevent
  Timeliness         engineers and partners                                                                     so accurate or timely
                                                    inaccuracies                  inaccuracies
                   • Very few false positives                                                                   protection may suffer
                                                                                                         *Cisco acquired ScanSafe & IronPort


                 For more information please visit: www.opendns.com or call 877-811-2367

More Related Content

PDF
Air defense wireless_vulnerability_assessement_module_spec_sheet
PDF
Holistic view of 802.1x integration & optimization
PPTX
Sasa milic, cisco advanced malware protection
PDF
[SOS 2009] D-Link: Red Segura L2 L3
PDF
Designing for the all wireless office ash chowdappa-kelly griffin
PDF
Minicom White Paper Using Ram To Increase Security And Improve Efficiency In ...
PPTX
PAN-OS - Network Security/Prevention Everywhere
PDF
Wlan wi ng5_brochure
Air defense wireless_vulnerability_assessement_module_spec_sheet
Holistic view of 802.1x integration & optimization
Sasa milic, cisco advanced malware protection
[SOS 2009] D-Link: Red Segura L2 L3
Designing for the all wireless office ash chowdappa-kelly griffin
Minicom White Paper Using Ram To Increase Security And Improve Efficiency In ...
PAN-OS - Network Security/Prevention Everywhere
Wlan wi ng5_brochure

What's hot (20)

PDF
LTE Testing
PDF
The Virtual Private Network
PDF
F5 beyond load balancer (nov 2009)
PPTX
Use Your IDS Appliance, presented by Kate Brew, Product Marketing Manager at ...
PPTX
802.11n: Platform vs. Point Solution
PDF
Airheads barcelona 2010 securing wireless la ns
PDF
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
PDF
Sonicwall wireless & sra
PDF
PDF
BreakingPoint & Fortinet RSA Conference 2011 Presentation: Evaluating Enterpr...
PDF
APManagement_FeatureGuide
PDF
1 voice and video over wi fi-balajee krishnamurthy
PDF
Dell sonicwall connected security
PDF
2012 ah apj rf troubleshooting
PDF
PPT
Capstone Presentation For Five Rivers Medical Centers
PPT
PDF
Ngfw overview
PDF
Has video really killed the audio star?
LTE Testing
The Virtual Private Network
F5 beyond load balancer (nov 2009)
Use Your IDS Appliance, presented by Kate Brew, Product Marketing Manager at ...
802.11n: Platform vs. Point Solution
Airheads barcelona 2010 securing wireless la ns
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Sonicwall wireless & sra
BreakingPoint & Fortinet RSA Conference 2011 Presentation: Evaluating Enterpr...
APManagement_FeatureGuide
1 voice and video over wi fi-balajee krishnamurthy
Dell sonicwall connected security
2012 ah apj rf troubleshooting
Capstone Presentation For Five Rivers Medical Centers
Ngfw overview
Has video really killed the audio star?
Ad

Similar to SWG Buyer Guide: Competitive Comparison (20)

PDF
OpenDNS Whitepaper: Platform Technology
PDF
Rugged DevOps Will help you build ur cloudz
PDF
Tech Doc: Umbrella Delivery Platform
PDF
Data Sheet: OpenDNS Enterprise Insights
PDF
OpenDNS Whitepaper: DNS's Role in Botnet C&C
PDF
Inside dropbox
PPTX
Home network security
PDF
Hosting
PPTX
#lspe: Dynamic Scaling
PDF
F5 Networks: architecture and risk management
PDF
Report Gartner Magic Quadrant For Security Web Gateway 2011 En
PDF
OCCI status update
PPTX
Intro to SDN - Part IV
PDF
Extranet topologies forsp 2010
PDF
Oit2010 model extranet_topologies
PPTX
Peernode
PDF
28th TWNIC OPM and TWNOG 2017: Security best practices for network operators
PDF
ION Mumbai - Shailesh Gupta: Business Case for IPv6 and DNSSEC
PDF
Cisco open network environment
PDF
Coolie @ call
OpenDNS Whitepaper: Platform Technology
Rugged DevOps Will help you build ur cloudz
Tech Doc: Umbrella Delivery Platform
Data Sheet: OpenDNS Enterprise Insights
OpenDNS Whitepaper: DNS's Role in Botnet C&C
Inside dropbox
Home network security
Hosting
#lspe: Dynamic Scaling
F5 Networks: architecture and risk management
Report Gartner Magic Quadrant For Security Web Gateway 2011 En
OCCI status update
Intro to SDN - Part IV
Extranet topologies forsp 2010
Oit2010 model extranet_topologies
Peernode
28th TWNIC OPM and TWNOG 2017: Security best practices for network operators
ION Mumbai - Shailesh Gupta: Business Case for IPv6 and DNSSEC
Cisco open network environment
Coolie @ call
Ad

Recently uploaded (20)

PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PPTX
Chapter 5: Probability Theory and Statistics
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PPTX
Tartificialntelligence_presentation.pptx
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Encapsulation theory and applications.pdf
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Approach and Philosophy of On baking technology
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
Getting Started with Data Integration: FME Form 101
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Group 1 Presentation -Planning and Decision Making .pptx
Chapter 5: Probability Theory and Statistics
Assigned Numbers - 2025 - Bluetooth® Document
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Tartificialntelligence_presentation.pptx
DP Operators-handbook-extract for the Mautical Institute
Encapsulation theory and applications.pdf
cloud_computing_Infrastucture_as_cloud_p
Heart disease approach using modified random forest and particle swarm optimi...
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Enhancing emotion recognition model for a student engagement use case through...
A comparative study of natural language inference in Swahili using monolingua...
Encapsulation_ Review paper, used for researhc scholars
Approach and Philosophy of On baking technology
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
Getting Started with Data Integration: FME Form 101
Digital-Transformation-Roadmap-for-Companies.pptx

SWG Buyer Guide: Competitive Comparison

  • 1. COMPETITIVE COMPARISON AND EVALUATION OpenDNS Enterprise vs. Web Proxies or Firewall Filters OpenDNS (step 1) delivers Internet-wide security and Web filtering leading competitive solutions, (step 2) which rely on lower performance, less effective Web proxy or firewall filter platforms. Replacing these traditional heavyweight solutions can significantly reduce on-going maintenance and secure Internet connections faster from every device on any number of networks, anywhere (compare the first two rows below). Alternatively, adding OpenDNS will extend protection to unmanaged devices or network locations where existing solutions are cost prohibitive, as well as reduce much of the unwanted heavyweight traffic from configured devices and networks clogging your existing solutions (compare the last two rows below). LIGHTWEIGHT TRAFFIC STEP 1 STEP 2 HEAVYWEIGHT TRAFFIC OpenDNS AUTHORITATIVE SAFE, FAST, SMART, ALL DEVICES, NO CLIENT SECURE, FAST TCP SERVERS DNS SERVERS RELIABLE RESPONSES OR NETWORK CHANGES INTERNET CONNECTIONS AND SITES NO LATENCY NO BOTTLENECKS Web Proxy or Firewall Filter AUTHORITATIVE NOT ALWAYS RELIABLE, CLIENT SETTINGS/SOFTWARE SOME SECURE, BUT SLOW, TCP SERVERS DNS SERVERS CONSISTENT RESPONSES OR NETWORK TOPOLOGY CHANGES INTERNET CONNECTIONS AND SITES 1 OR MORE ISPs PROXY FILTER Web Proxy or Firewall Filter plus OpenDNS AUTHORITATIVE SAFE, FAST, SMART, ALL DEVICES, PLUS SECURE, FEWER SLOW, TCP SERVERS DNS SERVERS RELIABLE RESPONSES ANY EXISTING CHANGES INTERNET CONNECTIONS AND SITES PROXY FILTER OpenDNS protects every device, which supports Bring Your Own Device (BYOD) programs, and secures every Internet connection, via a user interface not bloated with unused, complex bells and whistles. Like Web proxies and firewall filters, OpenDNS filters inappropriate sites for compliance, yet can easily scale from 1 to 1000s of network locations. ! BENEFIT SOLUTION " OpenDNS In-the-cloud Web Proxies On-premises Web Proxies On-premises Firewall Filters Protect every on-net device without client or network changes # $ Easy to manage without any $ MANY REQUIRE NEW software or hardware to maintain # % ON-PREMISES TRAFFIC TO REDIRECT DEVICES Secure any Internet connection – any application, protocol or port # $ Filter inappropriate sites and grant overrides to select users # Scale to 1000s of network locations cost-effectively # $ For more information please visit: www.opendns.com or call 877-811-2367
  • 2. Many security vendors focus on its solutions’ efficacy to block threats, but gloss over its usability or performance. USABILITY It is not uncommon for Web proxies and firewall filters to take days Vendors often assume administrators are to weeks before it is effectively enforcing devices and reporting investing their time in addition to their activity. Add on training to learn how to manage all the complex organization’s money to use the solution, bells and whistles, many which go unused, and on-going so they do not focus on how easy it is to: maintenance to address performance or efficacy issues, and the ownership cost increases. OpenDNS can enforce every device – on • provision and setup, any network – and report activity within an hour of asking for an • enforce and report, evaluation trial. Our simple Web-based management interface and issue-free operation, means you set and forget it. • manage and maintain. PERFORMANCE Often Web proxies and firewall filters are deployed within the Also, vendors often offer cryptic or rather network using a less redundant topology than if they never existed, meaningless specifications regarding the which can result in new points of failure. They add new hops for product’s performance, which do not Internet connections and/or processes applied to Internet traffic, always accurately reflect its: which can increase latency and decrease throughput; leading to less happy users. OpenDNS simply replaces a mandatory, already in-use • reliability and resiliency, service provided by Internet Service Providers (ISP). Our Anycast and • connection speed, and SmartCache technologies enable faster, more reliable Internet connections relative to most ISPs, by reducing hops and processes. • bandwidth throughput. EFFICACY Web proxies, in particular, provide minimal network coverage Finally, while vendors may claim they have depending on the setup of managed devices or networks. Often superior threat intelligence and only traffic sent by configured browsers is protected; not Web- prevention, consider more completely its: based outbound botnet traffic from infected devices’ malicious software. The Web may be the most used protocol, but it is one • network coverage, amongst hundreds that threats utilize and proxies are blind to. • threat coverage, Firewalls often only filter by destination for Web traffic; some using a built-in Web proxy. Firewalls filtering other protocol or application • accuracy and traffic often do not distinguish between good or bad destinations timeliness. for this traffic. OpenDNS ensures that malware, phishing, inappropriate sites and botnets never touch your network, regardless of application, protocol, port or device. OpenDNS maximizes the return on your security investments. PE TY RF ILI OR AB LOW TCO, MA The evaluation matrix on the following page provides US HIGH ROI, N more detail on how OpenDNS’s in-the-cloud solution CE HAPPY USERS compares to Web proxies – delivered in-the-cloud or on- premises – or on-premises firewall filters. We believe that you will draw the same conclusions, that OpenDNS EFFICACY delivers a more usable, high performance and effective solution than competitors’ traditional solutions.
  • 3. SOLUTION OPENDNS WEB PROXIES FIREWALL FILTERS Delivery • In-the-cloud • In-the-cloud • On-premises • On-premises Platform USABILITY • Lightweight DNS query • Receive and deploy • Receive and deploy • Heavyweight TCP traffic redirection without appliance per site appliance per site redirection per site network topology changes • Heavyweight TCP traffic • Significant configuration Provision • Requires network for 1 to 1000s of sites redirection per site to control network traffic & Setup • No appliances or client topology change, client • Requires network flow is likely required to software or setting software topology change, client migrate from current changes • No client setting changes software or changes firewall • Network-level granularity • User-level granularity via • Network-level granularity • User-level granularity via via public IP directory integration via internal IP directory integration Enforce • Grant override requires complex setup or • User-level granularity requires complex setup & Report permissions to users network-level granularity requires complex setup • Data retention limited by • Full data retention for 2 • Data retention often • Data retention limited by internal storage available years with no hidden fees limited or else extra fees internal storage available • Simple set and forget • Often security rules are • OS patch conflicts or • Complex and focused on • No OS patches or complex, and require upgrade downtime network management, not appliance upgrades fine-tuning to reduce • Often security rules are policy or security, so it is Manage & • No security rule tuning false positives/negatives complex and require fine- often confusing Maintain • SSL or auth. issues tuning • If SSL or auth. is • No site exceptions to address SSL decryption require frequent site • SSL or auth. issues included, then issues will or authentication issues exceptions require site exceptions require site exceptions PERFORMANCE • No outages since launch • Many have had outages • Often reduced network • Sometimes reduced Reliability & in 2006 despite SLA redundancy in topology or network redundancy in Resiliency • Uses Anycast IPs • Lack Anycast IPs else expensive topology • No new latency • Adds new latency due to • May add new latency • Often reduced response • Adds new latency due to another intermediate hop depending on internal Connection time via SmartCache one or more intermediate • Spikes in traffic will processes and the Speed • Spikes in traffic will not hops cause noticeably slower number of add-on cause slower speeds speeds features enabled • Virtually unlimited via • Likely unlimited, but • Limited by resources • Limited by resources Bandwidth lightweight queries & heavyweight traffic available on appliance or available on appliance or Throughput responses redirection can be limited server; often a bottleneck server EFFICACY • Depending on setup, only • Depending on setup, only • Any on-net device; • Any on-net device; managed devices and managed devices and managed or not managed or not configured browser configured browser • Filters by destination over Network • Filters by destination over applications applications HTTP/S, 80/443 Coverage any application, any • Filters by destination over • Filters by destination over • May include protocol or protocol and any port only HTTP/S and ports only HTTP/S and ports application filters, but 80/443 80/443 not by destination • Industry-leading • Ineffective outbound • Ineffective outbound outbound botnet protection due to protection due to • Outbound protection protection inadequate network inadequate network usually not a focus Threat • Inbound malware and coverage coverage • Inbound protection is Coverage phishing protection • Inbound protection use • Inbound protection use usually via 3rd-parties so • Web filtering categories proprietary and/or 3rd- proprietary and/or 3rd- efficacy is not controlled for regulatory & AUP party systems party systems • On-par Web filtering compliance • On-par Web filtering • On-par Web filtering • Proactive protection is • Not usually a core focus Accuracy & • Often need to fine-tune • Often need to fine-tune updated 24x7 via of business or products, security rules to prevent security rules to prevent Timeliness engineers and partners so accurate or timely inaccuracies inaccuracies • Very few false positives protection may suffer *Cisco acquired ScanSafe & IronPort For more information please visit: www.opendns.com or call 877-811-2367