netspoc v3.2发布

Network ">Security Policy Compiler (NetSPoC) 是一个用来管理大型计算机网络的安全策略的工具,可用来生成包过滤控制的配置文件以及安全域的边界配置。

New features:
 
·Support for Cisco ASA devices as packet filter, as VPN gateway and for LAN-to-LAN IPSec tunnels.
·Support "easy VPN" at Cisco VPN clients.
·Generated chains for Linux iptables are highly optimized now. Deeply nested chains are generated to minimize the number of tests for each checked packet.
·Support port address translation (PAT) to an interface for PIX and ASA.

Language:

·Changed syntax for defining crypto tunnels to support multiple VPN gateways.
·Renamed attribute "nat = .." at interface to "bind_nat = ..". This allows better distinction between binding and definition of NAT.
·Allow multiple NAT tags at attribute bind_nat of an interface. This simplifies definition of NAT for devices with multiple interfaces.
·Extended concept of secondary packet filter to "primary" packet filter. All rules which pass a primary filter are implemented as secondary filters on other devices
·Enhanced policy definitions to support template rule-sets which operate individually on each element of "users". This uses new keyword 'foreach' and nested expressions with 'user'. This concept replaces 'any:[local]' from previous versions.
·Added automatic group "network:[any:xx]", the group of all networks inside a security domain.
Removed "interface:xx.[back]". This was not widely used and can easily be expressed with complement: "interface:xx.[all] & ! interface:xx.[auto]".
·Renamed "interface:xx.[front]" back to the old syntax "interface:xx.[auto]" which was still valid syntax in previous versions.
·Added attribute "crosslink" for networks. A crosslink network combines two or more routers to a cluster of routers. Filtering occurs only at the outside interfaces of the cluster. The crosslink interfaces permit any traffic because traffic has already been filtered by some other device of the cluster.
·Added attribute "no_in_acl" for interfaces. With this attribute, no incoming ACL is generated for an interface. Outgoing ACLs are added to all other interfaces of the same device instead.
·Networks with isolated and promiscuous ports (RFC 5517) are supported now. Added attribute "isolated_ports" at networks and attribute "promiscuous_port" at interfaces. If a network has attribute "isolated_ports", hosts inside this network are not allowed to talk directly to each other. Instead the traffic must go through an interface which is marked as "promiscuous_port".
·Hosts no longer support multiple IP addresses, but only single IP addresses or ranges.
·Attribute "owner" no longer holds simple strings, but references to one or more 'admin', which has name and email address.

时间: 2024-09-24 02:49:14

netspoc v3.2发布的相关文章

OpenShift V3 应用发布部署的简单场景演示

本文讲的是OpenShift V3 应用发布部署的简单场景演示[编者的话]本文是一篇关于OpenShift如何应用在DevOps方面的文章.全文由浅入深,由易到难,通过3种不同场景下的部署,给读者一个对OpenShift功能的全新了解.译者以前和有些做容器开发,部署相关工作的同学认为:OpenShift仅仅是在Kubernetes基础之上架设了自己的WebUI,对API和CLI等接口进行了自己的封装(很多kubectl的命令都被oc继承).但是在接触了OpenShift 1个月后(翻译本文时,我

CYQ.Blog(QBlog) 单用户版本V3.0 发布下载[免费,简洁,高性能,双语言,8套皮肤,4种数据库支持]

前言说明:   秋色园QBlog,一直以来,都发布多用户博客版本,今天,终于提升了一个power,发布单用户博客版本了.   CYQ.Blog(QBlog) 特点:简洁,高性能,多语言,多数据库支持,可能支持linux下的mono部署运行.     基本介绍:   CYQ.Blog(简称QBlog)博客:下载地址:http://www.cyqdata.com/download/article-detail-427   本版本为免费版本,允许免费使用于商业与非商业(需要保留底部power by C

Basic4android v3.00 发布

     这次发布的版本主要是增加了快速debuger. 在运行时,可以在IDE 里面随时修改代码,而不需要重新发布应用. 大大提高了开发效率. Basic4android v3.00 is released. The main new feature in this version is the rapid debugger: Rapid Debugger The rapid debugger makes it much easier and quicker to test and debug

Basic4android v3.50 发布

     这次发布的主要是debug 的增强.说实话,在这一方面B4a 比delphi做的要好.希望delphi 在新的版本里面 能进一步加强.   I'm happy to release Basic4android v3.50. This update brings major improvements to the debugging features of Basic4android. With this update you can enjoy the rapidness and po

英特尔E5 v3平台发布 浪潮2路服务器M4家族同步上市

9月9日下午,英特尔在京发布了新一代英特尔®至强TM处理器E5 v3平台,英特尔PSR战略合作伙伴浪潮同步展出基于该平台的2路M4家族产品,浪潮相关负责人称,该家族产品已经可以对外批量供货. E5 v3在效率.性能功耗比和性能价格比上更具竞争力,在应用表现中更灵活.也更智能,可以帮助最终用户迎接移动互联和物联网时代的业务挑战.英特尔数据中心渠道市场总监Terry Thorn表示,E5 v3相比上一代产品可获得多达3倍的性能提升,这款处理器还能通过遥测技术提供关键参数,可以满足对软件定义基础设施(

基于C#+ArcEngine9.3开发的SimpleGIS V3.0发布

问题描述 SimpleGIS是基于C#+ArcEngine9.3环境开发的ArcEngine中间件产品,采用插件式开发机制,目前版本已更新至V3.0,在这个版本下,我们推出了土地定级模块和空间数据管理模块(数据库可采用Oracle或SqlServer).Demo版本请链接www.simplegis.com.cn/SimpleGIS.exe下载,如果你需要定制更详细的功能,可QQ:389240138,MSN:simplegis@hotmail.com安装程序中已把Oracle10客户端打包进安装程

Confluence v3.5发布 专业的企业知识管理与协同软件

Confluence是一个专业的企业知识管理与协同软件,一个专业的wiki.通过它可以实现团队成员之间的协作和知识共享.Confluence是由Atlassian公司推出的商业产品.Confluence使用简单,但它强大的编辑和站点管理特征能够帮助团队成员之间共享信息.文档协作.集体讨论. 功能列表: 知识管理:将人们聚集起来,在一起创建.更新和分享知识,发表自己的观点,并借此认识更多的知识作者. 企业门户:消除繁琐的信息发布流程,允许你的员工分享知识和观点,激励员工贡献自己的才能. 文档管理:

秋式网站日志分析器[IISLogViewer] V3版本发布

离上一个版本,过了好久好久了. V1.0时,叫:CYQ.IISLogViewer. V2.0时,给了个中文名,叫:点格网站日志分析器V2.0 升级到3.0了,给改了个名字,叫:秋式网站日志分析器V3.0   本次版本升级要点: 1:整体升级,避免线程冲突引发导致软件自动退出的问题. 2:分析格式升级,再精准分析IIS日志. 3:支持Linux下的IIS日志. 4:增加IP分析. 5:增加360搜索引擎的支持.   下面请看截图说明:   1:运行的界面,通过点击"单个文件"或"

WordPress v3.2发布 PHP语言开发的博客平台

WordPress 是一个注重美学.易用性和http://www.aliyun.com/zixun/aggregation/35911.html">网络标准的个人信息发布平台.WordPress 虽为免费的开源软件,但其价值无法用金钱来衡量. 使用 WordPress 可以搭建功能强大的网络信息发布平台,但更多的是应用于个性化的博客.针对博客的应用,WordPress 能让您省却对后台技术的担心,集中精力做好网站的内容. 服务器环境要求: ·PHP 5.2.4 或更新版本(不支持第三方推出