I need to create ACL to control access to 17 vlans

Hi,
we have created vlans based on departments, each department has its own vlan. as a result we have close to 17 vlans and this is in one site. we have 5 sites where all these vlans exist but with different subnets. my question has two parts:
1> I need ideas on what to block and what to permit? for example block all vlans from accessing all vlans except the server vlan, block all vlans from accessing storage vlan, allow internet traffic. permit the management vlan to access all vlans in one direction.
2>now i have to write access lists for each vlan, is there a way to ease the burden of creating 17*5  ACLs? for example create a generic acl and another one specific, but can I apply two access lists to one vlan at the same time.

Firs of all, 17 vlans is too much.. I don't think ther's real need so such a segregation. Are those all 17 departments should have their traffic separated from each other? Yeah, there's is might be couple departments with some highly secure traffic, but others probably can go in one VLAN. If no, then having 17 vlans with ACL on each, it's gonna be a real pain managing them.. But if it's already done, i may suggest to use some ACLs to protect really valuable resources from those, who shouldn't have access to them. For example you defenitely should have ACL on your server's VLAN and Storage VLAN. You can apply ACLs on this VLANs in outbound direction and be really granular in what you permit there and what is prohibited. Second, you can apply the same for your management VLAN, cause it's the other one with great value. But do you really have to restrict access from department A to department B if they kinda "have no secrets from each other"?. So my point is that your decision should be based on what you're really going to protect but not based on the fact that you're trying separate everything from everything just for fun). Cause again, if you separate everything with highly granular rules (i.e. host 1 from dep A should be allowed to host 1 from dep B but not host 2 from dep B, etc for other departments)  this all ruleset will be unmanagable. Things should be kept as simple as possible.

Similar Messages

  • Help needed for creating a SQLLoad control file

    I have 2 fields in my flat file
    If field1 = field2 load only field1 into tn and aux = NULL
    else if field1 != field2 load field1 into tn and field2 = aux
    Here is what I have so far - I need help with the "Where"
    -- ActiveNumbers.dat
    -- Steve J
    load data
    INFILE 'active.date'
    INTO TABLE tmp_ac_active
    APPEND
    FIELDS TERMINATED BY '|'
    (tn CHAR(10), aux CHAR(10))
    Thanks in advance
    Steve

    Thanks Joel
    Using the document you provided here is what I came up with. I notice this is 9i documents - I'm on 8. Does the SQLLoader work the same in both versions?
    This is the first time I've used this tool - No one here has even heard of it. (Well except for the DBA)
    load data
    INFILE 'active.date'
    -- Loads tn and aux if they do not match
    INTO TABLE tmp_ac_active
    WHEN tn != aux
    (tn CHARTERMINATED BY WHITESPACE,
    aux CHAR TERMINATED BY WHITESPACE)
    -- Loads only TN if both are the same
    INTO TABLE tmp_ac_active
    WHEN tn = aux
    (tn POSITION (1:10) CHAR)

  • How to create a new runtime access user - URGENT !!!!

    Hi,
    I already have an existing runtime repository and target schemas. I need to create a NEW runtime access user, as my old runtime access user was not available. could anyone please help me on this
    Kishan

    Hi,
    what OWB version? 10g R1?
    CREATE USER <user_name>
    IDENTIFIED BY <Enter User Password Here>
    GRANT CONNECT TO <user_name>
    GRANT WB_A_<RT_REP_name> TO <user_name>
    GRANT WB_D_<RT_REP_name> TO <user_name>
    GRANT WB_R_<RT_REP_name> TO <user_name>
    GRANT WB_U_<RT_REP_name> TO <user_name>
    Regards
    Detlef

  • Need create a new control key, which message control is "error mode", then PR or PO

    Hi All,
    Can please help me I got an issue in QM ,
    Issue Description :-  Current QM control key for supplier validation date is “0001”, the message mode is only warning. PR or PO still can be created forcibly. Need create a new control key, which message control is “error mode”, then PR or PO cannot be created successfully.
    I thing should add some additional logic using BADI or USER-EXIT.
    can please help me how to find BADI or USER-EXIT if you know the appropriate BADI please let me know.
    Regards,
    Nani

    Hi,
    I tried that way I entered message control as Defect even purchase requisition is created how can I restricted purchase request ion.
    Regards,
    Nani.   

  • "Sorry, you don't have access to this page" when creating a sub site. I am in the owners group with full control access

    cannot provisioning a SharePoint 2013 site with full control access, I get the page with the "Sorry, you don’t have access to this page”. Any help will be greatly appreciated.

    Hi,
    Which template did you use for the parent site?
    Please check whether the site collection administrator could create a subsite.
    Please grant permissions on the Device Channels list
    http://sitecollection_URL/DeviceChannels/AllItems.aspx -> List -> List Settings -> Permissions for this list -> granted Read rights for the Everyone group, compare the result as
    it.
    Please navigated to the hidden list "TaxonomyHiddenList" on the site collection i.e.
    http://somdnetsp/lists/TaxonomyHiddenList/AllItems.aspx and check permissions on this list. Check whether the list has unique permissions and there were no users added to the list. If yes,
    add "authenticated users" in the list permissions.
    Then, try to create sub site, compare the result.
    If this issue still exists, please check the log file to find whether there are some message about this issue.
    Best Regards,
    Wendy
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback
    for TechNet Subscriber Support, contact [email protected]
    Wendy Li
    TechNet Community Support

  • I wanted to send some photos out but was told I need to create a new profile, use mail icon in control panel no icon there how do I get it done?

    I want to send some photos from Firefox, when I tried it said I need to create a new profile, use mail icon in control panel. I went to control panel and do not know what to do.'''bold text'''

    As all of the msuic came from your computer in the first place it should still be there.  Is it not?
    EVERYTHING on your ipod should also be on your computer and should be included in your regular backup copy of your computer.
    Make sure that everything is on your computer.  You can transfer itunes purchases from the ipod.  Without syncing:  File>Transfer Purchases.
    When everything is on your computer, then it can be synced back to the ipod after updating.

  • I need to create a MIDI file with control cues only. Is that possible?

    I need to create a stand alone MIDI file with control cues to control a non-musical device which does understand these files.
    Must I create a virtual device in MIDI Setup for Logic to talk to?
    Must I create notes in order to create regions that will export?
    Is it possible to do this in MIDI channel 0?
    Is LogicPro the tool to use to do this?
    The maker of the device uses ProTools to create his MIDI files.
    I use a MacBook Pro with OSX 10.10.2 running LogicPro 10.1.1.
    Thanks!
    Doug

    No you cannot trigger a paragraph style with a character or character style.
    But you can have a Apply Next Character Style
    Accountable for: <paragraph style name "Heading 1">
    >> Bullet1 <paragraph style name "Bullet">
    In the Heading 1 style go to "Next Style" under "General"
    and choose "Bullet"
    The select from "Accountable for:" to the last bullet in the list
    Right Click on the Heading 1 style and go to Apply Heading 1 and Next Style.
    http://creativebits.org/indesign/taking_advantage_of_indesign_s_next_style
    http://indesignsecrets.com/where-is-apply-__-then-next-style.php

  • I need create a custom control for visualization HTML

    Hi guys,
      I need create a custom control for HTML files visualization on SAPGUI JAVA. I created a sample program and perfectly run on SAPGUI Windows.
    Thanks.
    Regards.
    Jose Antonio Campos.

    Hi,
    Just as a quick start
    http://gumbo.flashhub.net/sizer/  (view source enabled).
    this uses a skin to make a titlewindow resizable, its not about the skin as much as giving you a starting point for resizing code.
    if you look into the skin you will see these functions
    protected function sizer_mouseDownHandler(event:MouseEvent):void
    OldX=event.stageX;
    OldY=event.stageY;
    systemManager.addEventListener(MouseEvent.MOUSE_MOVE,startResize);
    systemManager.addEventListener(MouseEvent.MOUSE_UP,endResize);
    protected function endResize(event:MouseEvent):void
    systemManager.removeEventListener(MouseEvent.MOUSE_MOVE,startResize);
    systemManager.removeEventListener(MouseEvent.MOUSE_UP,endResize);
    private function startResize(event:MouseEvent): void
    hostComponent.width -= OldX-event.stageX;
    hostComponent.height -= OldY-event.stageY;
    OldX=event.stageX;
    OldY=event.stageY;
    The idea is to have a hit area on your custom component (a corner, or all corners). You capture the mouseposition when you mousedown then in the mouse move eventlistener you update the object size with the difference between current X and Y from initial X and Y.
    Hope this gets you started.
    David

  • Creating a cache control

    Has anyone created a cache control for Workshop?
    I'm wanting to cach the results of a complex report by using the xbean. Then if the request parameters match an already generated report, I simply send back out a pregenerated xbean.
    The cache would need a time expiration and max size handling.
    Thanks,
    Rodger Ball
    Sr. Software Architect
    Business Wire.

    If you have the option to use WLP, you can access the com.bea.p13n.cache APIs to write a Control that uses the portal cache functionality, which includes:
    * time-to-live (LRU removal), max size configuration
    * JMX based administration, including built-in admin from adminPortal and Workshop.
    * cluster aware flushing.
    Of course, if you can't or don't want to include portal, that won't work for you :)
    Greg
    Has anyone created a cache control for Workshop?
    I'm wanting to cach the results of a complex report
    by using the xbean. Then if the request parameters
    match an already generated report, I simply send back
    out a pregenerated xbean.
    The cache would need a time expiration and max size
    handling.
    Thanks,
    Rodger Ball
    Sr. Software Architect
    Business Wire.

  • Need design issue help regarding database access..

    I have an web application running on tomcat that will have access to a database connection pool. I have found a free java api that provides connection pooling. The code i will be using is:
    ConnectionPool pool = new ConnectionPool("local",
         10,
         30,
         180000, // milliseconds
         url,
         "b_lightyear",
         "BeyondInfinity");
    pool.getConnection();
    I need to put the above code somewhere where all my beans and classes can access it easily. I thought i would create a static class called DBConnector and have a getConnection() method to return a connection from the pool. However i would want the DBConnector class to be initialised on tomcat startup so that all the database pool can be initialised then. I dont see how i can do this? I know i can make a servlet initialised on tomcat startup but if i put the above code in a servlet how will i access it in my beans and java classes. I wont have the request, response objects available.
    Discuss.

    You should not need to 'control' access to the pool via a static method. The pool itself is probably implemented as a Singleton anyway. BTW, what pool are you using? DBCP from Jakarta is popular, stable and free.
    You use the Servlet's init() method for startup tasks and its destroy() method for clean-up tasks. Initialize your pool in the init() method of your Servlet. Simple. Just make sure you don't declare instance variables in your Servlet, can lead to thread-safety issues.
    BTW, love the Toy Story allusion! :^)
    - Saish

  • I need to prevent unauthorized users from accessing the application pages

    Hi^^,
    I have created an application in jsp and servlets. It has several pages like manager, supervisor accountant. I need to prevent unauthorised users from accessing these pages. In other words I need to implement a filter. Anyone who types a url other than that of the login page needs to be blocked. However I am not able to conceptualize the code that is going to be inside the doFilter() method. Please help
    Sincerely,
    Prashant

    Hi^^,
    I admit that there were some mistakes in the previous posting. I have corrected the mistakes and now there is going to be no compile time error. However when i put in the login id and the password it is redirecting me to the login page. I think that the front end jsp is directing the control to the controller servlet. But as "YOU" have pointed out in your previous post,
    "by default requestDispatcher.forward(...) does not pass through the filter change. If the user requests the login page from their browser however, then they will still get the error message, which may not be appropriate."
    I feel we need to somehow make the code pass through the requestDispatcher.forward(...) method of the servlet.
    I am again posting the corrected code.
    package com;
    import java.io.*;
    import javax.servlet.*;
    import javax.servlet.http.*;
    public class SecurityFilter implements Filter
      public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws   ServletException, IOException
      HttpServletRequest req = (HttpServletRequest)request;
      HttpServletResponse res = (HttpServletResponse)response;
      String X = req.getRequestURI();
      if(X.equals(http://localhost:8080/MyProject/LoginPage.jsp))
         //writing code for passing through the filter
         final class MyGenericFilter implements javax.servlet.Filter
          public FilterConfig filterConfig;
          public void doFilter( final ServletRequest request, final ServletResponse response, FilterChain chain) throws java.io.IOExeption, javax.servlet.ServletException
          chain.doFilter(request,response);
          public void init(final FilterConfig filterConfig)
          this.filterConfig = filterConfig;
          public void destroy()
    else
       HttpSession session = req.getSession();
       String username = (String)session.getAttribute("username");
       if(null==username)
         request.setAttribute("Error","Session has ended. Please login");
         RequestDispatcher rd = request.getRequestDispatcher("Login.jsp");
         rd.forward(request,response);
         chain.doFilter(request,response);
        else
         RequestDispatcher rd = request.getRequestDispatcher("X");
         rd.forward(request,response);
    public void init(final FilterConfig filterConfig)throws ServletException
          public void destroy()
      Edited by: pksingh79 on Aug 12, 2008 5:23 AM

  • Controlling Access of end users on Categories and Activity versions

    Dear All,
    I am having end users who are having full access in learning Administrator for Creating Categories and Activity versions , Offerings and Classes in using Learning Administrator responsibility.
    As per the business needs i need to create a new responsibility where end users can not create categories & Activity version but they can create only offerings & classes on selected Activity version.
    your guide lines will be greatly appreciated.
    Thanks & Regards,
    Edited by: user1113648 on Apr 28, 2011 11:55 AM

    Hi CDA
    You're not understanding the way Discoverer works. The lowest level of security control that can be applied inside Discoverer is at the business area level. Thus if a user has access to any part of a business area then they have access to the whole business area. This is done by your administrator using TOOLS | SECURITY from the Administration menu bar.
    The privileges that can be set using TOOLS | PRIVILEGES control what a user can do with the data that they have access to (remember that access itself is at the business area). Thus if a user has the Create / Edit workbook privilege and they have access to two business areas then they have that privilege for both business areas and create or edit workbooks to their heart's content in both of them.
    Further, and I think this is where you may be getting confused, you have to understand that an end user cannot grant the privilege for another end user to have access to their business area simply by sharing a workbook. The act of sharing a workbook does not share the access rights. In order for one user, aka the Registrar, to be able to run a workbook that was created by another user, aka the HR director), the Registrar must already have been granted access to the HR business areas by the Discoverer administrator. If a user does not have access to a business area but does have access to a workbook from that business area then they will not be able to execute the workbook.
    It therefore sounds like you do not have security under control.
    Best wishes
    Michael
    BTW: Are you using the SunGard Banner system by any chance, and are you using the ODS? If this is the case, you may be interested in knowing that my company has partnered with SunGard Higher Education to bring Discoverer training and consulting to their customers.

  • Creating ACLs via command-line

    Is it possible to create ACLs using a command-line utility?
    We are developing an application that will initially have 5000 users and will expand to 15000 users.
    When new users are detected in Microsoft Exchange we create a new user using the command-line (unix) but we also need to create a custom ACL for that user that includes existing ACEs for existing GROUPS that will be providing support.
    This is so that we can drop new Oracle reports into the users folders (again using command-line utilities) and have the reports use the ACL from the folder they are dropped into.
    Thanks for any help.
    null

    Thanks for your response Tom. See my post above 15 items down labeled 'TAR submitted ...'.
    Oracle provided sample code (listed in the above mentioned POST) that works just fine to create ACLs.
    I am very interested in your suggestion to us an agent though because there does not appear to be any way to 'manage' objects (delete groups/acls, etc) through XML.
    Also, Joyce indicated several weeks ago that Oracle does not support loading the class files and using Java from with Oracle DB to manage the objects.
    Our application will rollout in a few weeks and we still need to automate the management of user creation/deletion as well as ACL modification for over 5,000 users.
    The application is to automate the production and distribution of weekly reports using Oracle Reports server to produce PDF report files.
    The biggest problem area is not the mechanical process of creating the reports but rather the proper architecture to enable our customer service and technical support departments to assist the users when problems arise.
    Our current approace is:
    1. Create a custom ACL for each user with ACEs that allow the proper access by tech support and customer service.
    2. Create a report folder for each user, owned by system with the user's custom ACL applied to it.
    3. Automatically generate the reports with Oracle Reports server, and load them into IFS using XML files. Prior to the load IFSMODE is used to have the user's report folder ACL (the PARENT) assigned to the report when it is loaded.
    We would like tech support to be able to rerun a user's report if necessary but we can't figure out how to let tech support use the UI to submit the job to the report server, load the report into IFS and assign the proper ACL.
    Will the soon-to-be-released IFS 1.1 allow its Java classes to be loaded in the soon-to-be-released 8.1.7 so that IFS management can be handled from within the database?
    One last note - there are at least a dozen requests in this forum for more extensive documentation on using XML to automate the IFS functionality.
    I would be willing to assist in any such project you guys put together including, writing or proofing documentation, testing sample code, etc. I would need to do this after hours on my NT environment.
    Thanks again for the response.
    null

  • CcBPM - When we need to create Deadline branch?

    Dear All.
           Reffering to ccBPM - When we need to create Deadline branch? Thank you in advance.
    Cheers
    Yinglak

    Hi,
    Deadlines are used to end the corresponding open steps and proceed with either triggering an alert, throwing an exception or just continuing to the next step, depending on your needs. You define the maximum time given to a specific step to be executed in your process by using deadlines.
    From SAP Help:
    A deadline specifies the last point in time that the block can be executed. You can define a deadline as follows:
    &#9679;      The point in time when the step or process is generated
    &#9679;      An arbitrary point in time that you specify as an expression
    You define how you want the process to react if the deadline is exceeded in a separate branch. In this branch you can trigger an alert for Alert Management by using a control step, for example. The branch has read and write-to access to all data within the block.
    To define a deadline, call the context menu for that particular block.
    The system checks the deadline at runtime. If the deadline has been exceeded, the processing branch is executed for the deadline. The steps in the remaining processing branches in the block are not affected by this. In particular, note that these steps within a block are not automatically completed.
    You can find more information here:
    http://help.sap.com/saphelp_nw2004s/helpdata/en/de/766840bf0cbf49e10000000a1550b0/frameset.htm
    Regards,
    Gökhan

  • Do I need to create a view for this?

    Hi Ihave got 2 tables emp and project
    In emp tabe:
    emp_no
    family name
    given name
    In porgect table:
    emp_no
    status(assigned,unassigned)
    start_date
    end_date
    emp_no Family_name given_name
    1 Smith John
    In project table same employee can have many assigement eg
    emp_no status start_date end_date
    1 assigned 01-may-08 01-july-08
    1 assigned 01-sep-08 01-july-09
    1 unassigned 01-july-09 01-oct-09
    In the form:
    there are 2 querable fields "project ends between field1(date) and field2(date)" which is used to
    retrive records which have end date between field1 and field2.
    The following fields are needed to get from database:
    emp.family_name emp.given_name project.start_date project.end_date No.of time assigned
    Requirements:
    1. project.start_date and project.end_date must be the latest project_end_date for the same emp
    so in the above sample date
    2. No. of time assigned is a count of total of number records which have status='assign'
    So for the given sample data the record expected after query would be(field1=01-jun-08 field2=02-july-09)
    emp.family_name emp.given_name project.start_date project.end_date No.of time assigned
    Smith John 01-sep-08 01-july-09 2
    What is the best approach to get:
    1 The lastest project(latest end_date) for the emp
    2. get No.of time assigned.
    Do I need to create a view for this? If yes, any sample sql code this this?
    Thanks for your help

    Hi W1zard,
    Thanks for your reply. Could you clarify the following points for me:
    1.) you could create a master block basing on your emp table and a detail block basing on your project table with the relation over emp_no. set the default_where clause of your detail block programmatically using
    set_block_property('project', default_where, 'status = ''assigned'' and <your_date_criteria>');
    Q1: where I pit this code? in pre-query trigger in detail block?
    2.) Of course you could create a view to join both of your tables if you don't want to use master detail blocks; Also do the join over emp_no
    create or replace force view v_emp as
    select emp.family_name, emp.given_name, project.start_date, project.end_date
    from emp, project
    where emp.emp_no = project.emp_no
    Q2 As I mentioned before, there are multipal entries for the same emp in project table and we only need the maching record from project table which has latest end_date. So I think I need something like
    max(project.end_date) somewhere in create view to make sure only one record for one employee.
    Also is there possible to include the no. of assigned field(select count(*) from project where status='assigned' and emp=emp_no) into the view as well?
    Q3 All the fields mentioned above are diaplay-only. So Can I create a control block which has all the fields from emp and project. Then populate them with my sql. The question is
    where I put this customerised sql so when user click excute query. My sql will run and display one the form?
    REally appreciated your help!
    Michael

Maybe you are looking for

  • Check if refreshing data in pivot table was finished

    Hello guys,  This is my first post here so forgive if I'm asking in wrong place.  Maybe you can help me or give me some hint how can I check if data in pivot tables refresh event was finished. So I'm using excel plugin that allows to load excel sprea

  • Grouping of key figures

    Hi Gurus! I need your advice. For example in our BEx query we have  a lof of key figures (AB, AS, AD, BS, BD, BG, CF, CA...) in columns. And we would like to disjoint them by additional row with captions A, B, C.. like following: A                  

  • FI-GL(Income Statements) problems while extracting from R/3?

    Hi Guru's, I will be working on FI-Gl(Income Statement) for the first time, could someone please tell me what problems i would face when getting data from R/3. I have read that they are few problems in transferring Special Ledger Data from R/3. Like:

  • Burning a  large mp3, I would like to start on burning vd #4

    The electricty went off and left me at 6 of 8

  • Finding correlation using derived columns?

    I want to use the aggregate CORR_S function which take two numerical columns and output the correlation between them. Assuming I have the table: Employee(name, gender, salary) where I want to create two derived columns, how would I do it? Like, SELEC