SunScreen 3.1 Reference Manual

Configuration

A configuration is the union of one policy with the common objects to form a complete description of the behavior of one or more Screens. A policy is a named set of policy objects. For example, when the SunScreen software is first installed, there is one policy, named Initial. Common objects are data objects relevant to all policies. Object types are either named or ordered. Named common object types include address, screen, service, interface, certificate, and time objects. Ordered objects include filtering rules, NAT rules, administration access rules, and VPN gateway descriptions. Neither common objects nor rules include objects loaded into SKIP but they do include the reference from the certificate name in the common object registry to the internal identity used by SKIP.