Network Dictionary – Positive Enforcement

Positive Enforcement is consultant babble for the standard configuration of a firewall or access list to “DENY ALL”.

See also Application Delivery Controller

About Greg Ferro

Greg Ferro is a Network Engineer/Architect, mostly focussed on Data Centre, Security Infrastructure, and recently Virtualization. He has over 20 years in IT, in wide range of employers working as a freelance consultant including Finance, Service Providers and Online Companies. He is CCIE#6920 and has a few ideas about the world, but not enough to really count.

He is a host on the Packet Pushers Podcast, blogger at EtherealMind.com and on Twitter @etherealmind and Google Plus

  • Mike Crowe

    Within the DoD realm of the US government, the term they’ve tried to standardize (but it’s not often heard) is “DAPE” – Deny All, Permit by Exception.
    Positive Enforcement sounds like it developed out of the whole “participant trophy, everyone’s a winner” mindset. Ugh.