OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

openc2-actuator message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Specifiers for virtual actuators


Actuator Profile Subcommittee, 
 
We are currently resolving comments to the stateless packet filtering profile.  We defined three specifiers so that the orchestrator can direct a command to the firewall(s).
*	Hostname
*	Named_group
*	Asset_id 

The gist of a comment we received was that these specifiers are not sufficient to cover the network function virtualization use case.  For example, the amazon web service requires the following in order to identify the firewall with sufficient precision:  
*	"aws_account_id" : "123445689",  
*	"aws_region" : "us-east-1",
*	"aws_vpc_id": "vpc-123",
*	"aws_nacl_id": "acl-123"
 
We need to define in a generic manner the specifiers needed to accommodate the network function virtualization use case and propose that this should be a topic for the next actuator profile subcommittee meeting.  
 
Your thoughts?  
 
VR
 
Joe Brule



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]