BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//HENC//Workshop//EN
METHOD:PUBLISH
BEGIN:VEVENT
UID:henc-session-7@henc.net.unc.edu
SEQUENCE:2
DTSTAMP:20260919T082435Z
DTSTART:20260929T213000Z
DTEND:20260929T222000Z
SUMMARY:Vendor-neutral firewall automation
LOCATION:Main Room\, Metropolitan State University of Denver | CAVEA Theate
 r\, Denver\, CO
DESCRIPTION:In spring 2026 Dartmouth College deployed a vendor-neutral fire
 wall automation process. The goals were to allow groups around campus to s
 ubmit their own changes\, allow for a review and auditing process\, to bui
 ld in automatic validations that the intent of the firewall rules are pres
 erved\, and to allow the firewall policy to apply without modification acr
 oss all campus firewalls. The long-term goal is that if we change firewall
  vendors we will be able to keep the same workflows and policies\, effecti
 vely abstracting away the vendor-specific aspects of the firewall.\n\nWe
 ’ll go over the basic design as well as how the firewall automation ties
  in to our existing network automation. We’ll also go over some features
  that we’re hoping to include in future iterations\, such as full modeli
 ng devices in batfish to test network connectivity\, as well as safely all
 owing object definitions in a central API-accessible database to be synced
  from other automation sources around campus.  The base of the design are 
 objects that are part of object groups\, with the object groups being refe
 renced in the policy rules. There are additional checks that get run with 
 each change to the firewall rules (such as verifying that the public DNS s
 ervers are always reachable). These checks verify that earlier rules don
 ’t change the traffic flow for later rules and unexpectedly permit or de
 ny traffic. We’ll go through the workflow for making changes as well as 
 how that might change in the future.
END:VEVENT
END:VCALENDAR
