Great Circle Associates Network-Automation
(May 2005)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ACL compiler [was: Network Automation: An Architects View]
From: Kon Wilms <kon @ datacast . biz>
Date: Tue, 24 May 2005 11:07:17 -0700
To: DJ Gregor <dj @ gregor . com>
Cc: network-automation @ greatcircle . com
In-reply-to: <66b6f3369bde6fa64632f383d2bc4500@gregor.com>
References: <5.1.0.14.0.20050521155048.025ab230@mail.eclipse.co.uk> <17039.36357.794569.744848@perdition.linnaean.org> <c0fc3ae805052217037a1c0971@mail.gmail.com> <20050524115708.E40415@skink.reptiles.org> <66b6f3369bde6fa64632f383d2bc4500@gregor.com>

On Tue, 2005-05-24 at 12:25 -0400, DJ Gregor wrote:
> I've also seen the same thing done in a commercial product where not  
> only the firewall configuration, but the entire device configuration  
> was specified in an XML language that was translated to operating  
> system-specific configurations (for multiple OSes, even).  The XML  
> configurations were per-device, not per-network, however.

We use this kind of approach on our embedded receivers. The entire
configuration of the receiver (they run embedded linux) from the network
addresses down to the software and daemons is ruled by a configuration
daemon that uses a pseudo-xml structured file to retrieve settings. The
delivery of these configurations are done to targeted devices, which may
be a single device or a group of devices (a group is used
interchangeably). Configuration data can also update the entire box (new
firmware and configuration) or only a subset of sections (all firewall
configuration files, or just the ip address). Using the group IDs with
masking and conflict management at the management system you can do per
device and per network configurations.

Cheers
Kon




References:
Indexed By Date Previous: Re: ACL compiler [was: Network Automation: An Architects View]
From: DJ Gregor <dj@gregor.com>
Next:
From: (nil)
Indexed By Thread Previous: Re: ACL compiler [was: Network Automation: An Architects View]
From: DJ Gregor <dj@gregor.com>
Next: Re: ACL compiler [was: Network Automation: An Architects View]
From: "Francis Liu" <Francis.Liu@optus.com.au>

Google
 
Search Internet Search www.greatcircle.com