Single-Pass Architecture

Single-Pass Architecture is a processing architecture for network security platforms in which traffic is decrypted, decoded and classified only once and all inspection functions work on this common pass. The counter-model is the chaining of separate inspection systems (service chaining), in which each function processes the traffic anew.

In a single-pass architecture, functions such as firewall, intrusion prevention, web filtering, malware detection and data loss prevention share the information about application, user and content determined once. This avoids multiple processing, reduces latency and facilitates a uniform policy model, because all functions access the same context. With service chaining, by contrast, additional delays and separate rule sets arise that have to be maintained individually.

As a product term, single-pass is used above all by two vendors: Palo Alto Networks calls the architecture of its next-generation firewalls Single-Pass Parallel Processing (SP3), and Cato Networks calls the inspection engine of its cloud platform Single Pass Cloud Engine (SPACE). Generically, both describe the same principle. The place of processing differs: Palo Alto Networks combines single-pass software with parallel special-purpose hardware in firewall appliances, while Cato processes the traffic as software in the PoPs of a cloud service. Cloud-based, the principle is the basis of many offerings for Firewall as a Service (FWaaS) and frequently a core element of a SASE platform.