Back to selected work

Explainable network segmentation

FortiFlow2

Turn traffic observations into traceable, controlled and understandable FortiGate policy proposals.

StatusFunctionally validated candidate · final confidence review planned
Public source
Decisions workflow Observed flows → Decisions → Policy proposal. Fictional data Observed flows01 Decisions02 Policy proposal03 Fictional data

01

The problem

Network logs provide evidence of communications, not a safe and usable policy by themselves. Aggressive aggregation can create source × destination × service combinations that were never observed.

02

My role

Product framing, network/security invariants, prioritisation, decision validation and orchestration of development through the test runtime.

03

Key decisions

  1. Keep observed flows as source evidence and every policy traceable back to them.
  2. Separate exact strategies from controlled generalisation and measure any expansion explicitly.
  3. Resolve proven cases automatically and keep ambiguous cases fail-closed for an engineer’s decision.
  4. Use one backend engine for preview, preflight, metrics and generation.

04

Demonstrable outcome

The current candidate passes a complete 310-test suite and the analysis → preview → preflight → generation workflow. In the documented representative replay, Balanced and Compact keep Additional = 0. Final qualification for pre-deployment use with engineer validation remains intentionally subject to a separate confidence review.

05

Technologies

  • Node.js
  • JavaScript
  • Docker
  • FortiGate
  • FortiAnalyzer
  • Playwright

AI assistants accelerated parts of the design and development work. Network/security decisions, acceptance criteria, testing and validation remain human-led and human-verified.