Enterprise Networking

Vendor-neutral firewall automation

Tuesday, September 29 · 3:30–4:20 PM America/Denver · Main Room

In spring 2026 Dartmouth College deployed a vendor-neutral firewall automation process. The goals were to allow groups around campus to submit their own changes, allow for a review and auditing process, to build in automatic validations that the intent of the firewall rules are preserved, and to allow the firewall policy to apply without modification across all campus firewalls. The long-term goal is that if we change firewall vendors we will be able to keep the same workflows and policies, effectively abstracting away the vendor-specific aspects of the firewall.

We’ll go over the basic design as well as how the firewall automation ties in to our existing network automation. We’ll also go over some features that we’re hoping to include in future iterations, such as full modeling devices in batfish to test network connectivity, as well as safely allowing object definitions in a central API-accessible database to be synced from other automation sources around campus. The base of the design are objects that are part of object groups, with the object groups being referenced in the policy rules. There are additional checks that get run with each change to the firewall rules (such as verifying that the public DNS servers are always reachable). These checks verify that earlier rules don’t change the traffic flow for later rules and unexpectedly permit or deny traffic. We’ll go through the workflow for making changes as well as how that might change in the future.

Paul Schmidt

Paul Schmidt

Dartmouth

Schmidt is the Network Architect for Dartmouth College and leads the team of Network Engineers. He is a member of the NEREN technical committee and the co-chair for the Advanced Networking track at this year's Internet2 Technical Exchange conference.

Add to calendar ← Back to schedule