[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Future
of Network Partitioning (1/2)
X.509 certificates
to replace IP addresses for device & hosts identification & authentication
The same as IPsec
User-based
access control
Filters based on user X.509 certificates
Using HTTP AAA
Recall: in existing
network devices
: at the
network layer
How user-based filtering works
The first network device that a host tries to cross authenticates the user
The network device applies the user profile
The user only sees a virtual network with the specific hosts and services he needs access to
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 34 -