Dynamically Extensible Policy Server and Agent

  • Authors:
  • Y. Kanada

  • Affiliations:
  • -

  • Venue:
  • POLICY '02 Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks (POLICY'02)
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes a method, called the policy-extension-by-policy method, for quickly and dynamically adding policyclasses with new functionality to policy servers and agents. In this method, users can add a new policy class to the policyserver by using policy-definition (PD) policies, and they can define a method to translate a policy of the new class and to sendto network nodes of different vendors through various types of device interfaces, such as CLI, MIBs, PIBs, APIs or hardwaretables, by using policy-embedding (PE) policies. A PE policy also enables translating a policy of an existing class andsending the result to a new type of network node. PE policies contain command templates and methods for filling thetemplates. A program interpreter is embedded in policy agents to make flexible policy-to-configuration translation possible. Aprototype system and example policies, i.e., access control, Diffserv, and VPN policies, were developed.