[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Security policy
Security policy
In applications
DBMS, multicast, ...
In operating systems
User level in distributed applications or resources
In the network
Network security policy in
IPsec
,
The IPsec policy database filters contain
selectors
and
policies
Selector is source IP address, destination IP address, protocol, source port, destination port
Policy is the rule: allow / deny / encrypt, like in access lists that apply to datagrams
Policy indicates what tunnels IKE should set-up
Policy in IPsec is rules for one endpoint
Too often: a single rule for one device = "a policy"
If <condition> then <action>
Source @IP, dest @IP, protocol, service, then allow/deny
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 50 -