Explainable network segmentation
FortiFlow2
Turn traffic observations into traceable, controlled and understandable FortiGate policy proposals.
01
The problem
Network logs provide evidence of communications, not a safe and usable policy by themselves. Aggressive aggregation can create source × destination × service combinations that were never observed.
02
My role
Product framing, network/security invariants, prioritisation, decision validation and orchestration of development through the test runtime.
03
Key decisions
- Keep observed flows as source evidence and every policy traceable back to them.
- Separate exact strategies from controlled generalisation and measure any expansion explicitly.
- Resolve proven cases automatically and keep ambiguous cases fail-closed for an engineer’s decision.
- Use one backend engine for preview, preflight, metrics and generation.
04
Demonstrable outcome
The current candidate passes a complete 310-test suite and the analysis → preview → preflight → generation workflow. In the documented representative replay, Balanced and Compact keep Additional = 0. Final qualification for pre-deployment use with engineer validation remains intentionally subject to a separate confidence review.
05
Technologies
AI assistants accelerated parts of the design and development work. Network/security decisions, acceptance criteria, testing and validation remain human-led and human-verified.