How to automate the design of firewalls ?
Shenzhen 10Gigabit Ethernet Technology Co.,ltd
Empowering Communication, Securing Networks - Your Trusted Partner for a Connected World
Fancy Wang 1005 2022
Firewall Automation Design
The SDN controller is connected to the Openstack cloud platform, and the FWaaS plug-in is installed on the Neutron module. The OpenStack cloud platform manages the firewall (FW) service through the FWaaS plug-in, and connects to the network controller to realize the automatic configuration of the second and third layers of the FW.
Different services are isolated by VPN on the gateway, and different and mutually isolated vFWs are created on the FW. The traffic that accesses the outside on the vFW is introduced into the root wall first, and then accesses the outside. The principle of FW automation is shown in the figure.
Pre-configuration is required on the FW so that the network controller can manage the FW. The pre-configured content includes the management IP address of the FW, NETCONF parameters, and the interconnection static route between the FW and the gateway switch VS1 (northbound default route and southbound large network segment route)
领英推荐
The automatic configuration process of the FW is as follows.
The traffic model designed by FW automation is as follows.