[Agenda]
[Examples]
[Network Partitioning]
[Policy]
[Concepts]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Network access security policy
Network access security policy
Globally design and enforce access to network components between domains
Network security policy in products
Checkpoint FW-1 OSM & Cisco Security Manager:
policy = set of
filtering rules
within the software, an access-list
configuration tool allows
template
rules
no
network knowledge:
user
must compute
manually
to which devices each set of rules should be applied to
Solsoft Net Partitioner:
policy = the security policy for the business needs:
meta-policy
policy definition tool allows
global
rules, including template rules
network knowledge:
software
computes
automatically
on which devices each rule should be applied
® ©
Hervé Schauer Consultants
August 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 27 -