Network Access Control Method with Excessive Filtering Rules
【Abstract】After analyzing the excessive filtering rules, a solution to increase the performance of network access control equipment is proposed.Based on ideas of optimizing rules and load balance of multi-equipment, the approach of Serial Double-separation Access Control(SDAC) method isput forward. In this method, organizing source IP into groups (control of source address) is separated from opening access port (control of service),and the management of firewall is separated from the optimization of access control. Double firewall serial setting scheme for the first separation andoptimizing rules scheme for the second separation are designed. Feasibility and superiority of SDAC are proved by physical simulation experiments.
一共有 2 条评论