[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Network access security policy
Network access security policy
Globally design and enforce access to network resources between
domains
Apply on
LANs
&
WANs
Based on IP filtering
Network security policy in products
Checkpoint FW-1 OSM & Cisco Secure PM:
policy = set of
filtering rules
within the software, an access-list
configuration tool allows
template
rules
no
network knowledge:
user
must compute
manually
which devices each set of rules should be applied to
Solsoft Net Partitioner:
policy = the security policy for the business needs:
meta-policy
policy definition tool allows
global
rules, including template rules
network knowledge:
software
computes
automatically
which rules should be applied to which devices
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 51 -