[Agenda]
[Examples]
[Network Partitioning]
[Policy]
[Concepts]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Security policy
Security policy
Within applications . DBMS, multicast, ...
Within operating systems
User level in distributed applications or components
...
Network security policy in IPsec,
Refers to the policy database
Set of rules: allow / deny / encrypt, like access lists that apply to datagrams
What tunnels IKE should set-up
Policy rules for one endpoint
Too often: a single rule for one device = "a policy"
If <condition> then <action>
Source @IP, dest @IP, protocol, service, then allow/deny
® ©
Hervé Schauer Consultants
August 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 25 -