首页> 外国专利> Method and machine for centralized configuration of firewall in TCP/IP internet protocol data system, system description specification is separated from access control policy in form of access rule between origin and destination resources

Method and machine for centralized configuration of firewall in TCP/IP internet protocol data system, system description specification is separated from access control policy in form of access rule between origin and destination resources

机译:在tcp / ip网际协议数据系统中进行防火墙集中配置的方法和机器,系统描述规范以源与目的资源之间的访问规则形式与访问控制策略分离

摘要

The method has: (a) a description stage for each resource (7) of the data system (3), via a graphical and data collector interface (8);a description stage, via the graphical and data collector interface, for an access control rule, between a origin resource and a destination resource, allowing definition of an access control policy between the two resources;the two stages are realized in an independent manner The firewall (2) configuration device, for a data system (3) includes a central configuration machine (5) having (a) a graphical interface (8) describing the system and access control policy to the resources (7); (b) a compilation motor (9) which translates the collected data from the interface (8) in access control rules; (c) a teleloading and synchronizing module (10) designed to ensure transfer, of the rules created by the motor (9), to the appropriate firewall. The module (10) communicates with the group of firewalls, at the instant which the new transferred rule files are taken into account and applied.
机译:该方法具有:(a)经由图形和数据收集器接口(8)的数据系统(3)的每个资源(7)的描述阶段;经由图形和数据收集器接口的访问的描述阶段。在源资源和目标资源之间的控制规则,允许定义两个资源之间的访问控制策略;这两个阶段以独立的方式实现。数据系统(3)的防火墙(2)配置设备包括:中央配置机(5)具有(a)图形界面(8),该图形界面描述系统和对资源(7)的访问控制策略; (b)编译马达(9),其将来自接口(8)的收集的数据转换成访问控制规则; (c)远程装载和同步模块(10),用于确保将电动机(9)创建的规则传输到适当的防火墙。在考虑并应用新传输的规则文件时,模块(10)与防火墙组进行通信。

著录项

相似文献

  • 专利
  • 外文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号