[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Limitations
of Network Partitioning
IP address based
Why trust IP addresses?
LAN security is needed
DHCP
Binding IP address to MAC (Ethernet) address
Becomes complex in large environments
Meshed networks with large numbers of filtering devices
When business needs require the set up of many VLANs
Definition is too complex when many entities have exchanges
Many branches with different flows between them
templates can't be used
Need for local policy definition within a hierarchical policy definition
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 28 -