Title :
Integrating changes to a hierarchical policy model
Author_Institution :
Cisco Syst., Inc., Champaign, IL, USA
Abstract :
Cisco´s VPN and security management system (VMS) is based on a hierarchical security policy model. Customers have found this hierarchical composition policy model a clear and succinct form for expressing policy enforced by multiple security devices. However, many customers also need to make changes to their Cisco devices directly via command line interface (CLI) to trouble shoot or deal with an immediate problem and then reintegrate the semantic changes back into the VMS policy. This paper outlines techniques for reincorporating such out of band, low level configuration changes back into the common hierarchical policy model.
Keywords :
telecommunication network management; telecommunication security; virtual private networks; command line interface; hierarchical composition policy model; hierarchical security policy model; security management system; Aggregates; Intrusion detection; Security; Utility programs; Virtual private networks; Voice mail;
Conference_Titel :
Integrated Network Management, 2005. IM 2005. 2005 9th IFIP/IEEE International Symposium on
Print_ISBN :
0-7803-9087-3
DOI :
10.1109/INM.2005.1440815