Great Circle Associates Network-Automation
(May 2005)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ACL compiler [was: Network Automation: An Architects View]
From: Cat Okita <cat @ reptiles . org>
Date: Tue, 24 May 2005 11:58:30 -0400 (EDT)
To: Lori Barfield <itdirector @ gmail . com>
Cc: network-automation @ greatcircle . com,Ian Glossop <ian . glossop @ glomal . co . uk>,Daniel Hagerty <hag @ linnaean . org>
In-reply-to: <c0fc3ae805052217037a1c0971@mail.gmail.com>
References: <5.1.0.14.0.20050521155048.025ab230@mail.eclipse.co.uk> <17039.36357.794569.744848@perdition.linnaean.org> <c0fc3ae805052217037a1c0971@mail.gmail.com>
Reply-to: Cat Okita <cat @ reptiles . org>

On Sun, 22 May 2005, Lori Barfield wrote:
> well, i wouldn't limit the solution to an ACL compiler; i'd shoot
> for the whole kit, where the security policy is defined with a strict
> syntax, and that is interpreted to create baseline executable
> configuration instructions for traffic-bearing devices at various
> layers.

Heh. I floated that idea by on firewall-wizards a while back, and it's
really not at all a trivial problem or an easy solution.

Each device and vendor uses slightly different syntax, and producing
an agreeable meta-language is a right pain in the keister.

cheers!
==========================================================================
"A cat spends her life conflicted between a deep, passionate and profound
desire for fish and an equally deep, passionate and profound desire to
avoid getting wet.  This is the defining metaphor of my life right now."


Follow-Ups:
References:
Indexed By Date Previous: Re: ACL compiler [was: Network Automation: An Architects View]
From: Lori Barfield <itdirector@gmail.com>
Next: Re: ACL compiler [was: Network Automation: An Architects View]
From: DJ Gregor <dj@gregor.com>
Indexed By Thread Previous: Re: ACL compiler [was: Network Automation: An Architects View]
From: Matt S Trout <network-automation@trout.me.uk>
Next: Re: ACL compiler [was: Network Automation: An Architects View]
From: DJ Gregor <dj@gregor.com>

Google
 
Search Internet Search www.greatcircle.com