About Security
CHAPTER 8
Policies
The purpose of a Firebox Vclass appliance is to deter-
mine whether data is to be passed or blocked and, if
passed, what action will be taken with the data. The
set of rules by which data is evaluated and managed is
called a security policy.
About Security Policies
Every security policy operates in a similar way: it lists
qualifications that the Firebox Vclass appliance uses as
it analyzes the initial packets of a new stream of data.
The sources of data can be your internal network or
any external networks including the Internet. Then, if
the packets match the traffic specifications of a given
policy, the appliance can take several types of actions:
firewall actions, proxy actions, IPSec actions (involv-
ing manual-key or automatic-key encryption and
authentication), a variety of NAT/load-balancing
actions, and QoS actions.
Firebox Vclass User Guide
159