[Agenda] [Examples] [Network Partitioning] [Policy] [Concepts] [Process] [Organization] [HW-SW] [Cases studies] [Conclusion] [Resources]
[first slide] Network access security policy [previous slide] [next slide]


* Network access security policy
o Globally design and enforce access to network components between domains

* Network security policy in products
o Checkpoint FW-1 OSM & Cisco Security Manager:
   - policy = set of filtering rules within the software, an access-list
   - configuration tool allows template rules
   - no network knowledge: user must compute manually to which devices each set of rules should be applied to
o Solsoft Net Partitioner:
   - policy = the security policy for the business needs: meta-policy
   - policy definition tool allows global rules, including template rules
   - network knowledge: software computes automatically on which devices each rule should be applied

*********************************************************************
HSC ® © Hervé Schauer Consultants August 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 27 -