首页> 外国专利> Method of configuring of firewall in TCP/IP Internet system, having access control policy agents so as to control an interior domain from an exterior domain, using an access control rule between origin and destination resources.

Method of configuring of firewall in TCP/IP Internet system, having access control policy agents so as to control an interior domain from an exterior domain, using an access control rule between origin and destination resources.

机译:在TCP / IP Internet系统中配置防火墙的方法,该方法具有访问控制策略代理,以便使用源和目标资源之间的访问控制规则从外部域控制内部域。

摘要

The method regroups the system objects by protection domain (5,6). Each firewall (1) assures the protection of an interior domain (5) with respect to an exterior domain (6).A access control rule is applied to the particular fire wall so as to control access between an origin resource (4) and destination resource uniquely if both resources belong to the same domain (5,6). Network or sub-networks for firewalls (10) to which the zones (8) are connected are associated with an interior or exterior domain. Network (10) interface inputs and outputs are determined for the traffic during processing and the attachment of the network interfaces to an interior or exterior domain is determined. A unique rule is applied if the two interfaces are attached to the same interior domain (5) which corresponds to the resources belonging to the same protection domain. The method comprises a group of objects (3) for which the access control policy is identical and applies the rule between each of the resources of an origin group and a destination group. The rule has a local range or a global range and it is applied to concerned resources uniquely if the resources belong to the same protection domain when the range of the rule is local and is applied to all the concerned resources when the range of the rule is global.
机译:该方法按保护域(5,6)重新组合系统对象。每个防火墙(1)确保相对于外部域(6)保护内部域(5)。将访问控制规则应用于特定防火墙,以控制源资源(4)与目标之间的访问如果两个资源都属于同一个域,则资源唯一(5,6)。区域(8)连接到的防火墙(10)的网络或子网与内部或外部域相关联。确定网络(10)接口的输入和输出以用于处理期间的业务,并确定网络接口到内部或外部域的连接。如果两个接口都连接到与属于同一保护域的资源相对应的相同内部域(5),则将应用唯一规则。该方法包括一组对象(3),对其的访问控制策略是相同的,并且在源组和目的组的每个资源之间应用规则。规则具有本地范围或全局范围,并且当规则的范围为本地时,如果资源属于同一保护域,则该规则唯一地应用于相关资源;而当规则的范围为本地时,则应用于所有相关资源全球。

著录项

  • 公开/公告号FR2802667A1

    专利类型

  • 公开/公告日2001-06-22

    原文格式PDF

  • 申请/专利权人 BULL SA;

    申请/专利号FR19990016118

  • 申请日1999-12-21

  • 分类号G06F13/10;H04L12/28;

  • 国家 FR

  • 入库时间 2022-08-22 01:07:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号