A Reference Model for Firewall Technology and its Implications for Connection Signaling
J. Bryan Lyles, Christoph L. Scuba · 1996
This paper concentrates on one particular aspect of providing communication security: firewalls between domains of trust. We argue that signaling support for providing scalable security services is a design requirement. On this basis we outline a reference model for firewall technology. It captures the current state of the art and proves suitable for connection-oriented high-performance networks. The architecture is an improvement in network management and provides a controlled exposure of the internal network structure to the outside, and transparency to the user. Its components are endpoint authentication, call admission control, connection authentication, audit, and a distributed architecture with centralized policy. The paper discusses implications of this reference model for the design of signaling protocols.