Uploaded June 2025 | Updated September 2026, 1 week ago
Managing millions of access rules across large network infrastructures is a daunting task. These networks contain devices from multiple vendors, each with different syntax and different system capabilities. At Meta, we've tackled this challenge by designing a pipeline that streamlines access request onboarding while ensuring uninterrupted network access. Our pipeline automates the configuration rendering process, reducing manual efforts and minimizing the risk of errors.
We will be talking about adopting CAPIRCA, a firewall and network security policy management tool, to create vendor-agnostic configs that simplify our network infrastructure. After onboarding Capirca from the open-source world, we’ve made some significant changes to it. This helped us with building various services around Capirca, including a service for users to trace their access, deep inspect user changes and add auditing systems that be run ad-hoc to audit our access rules.
To further strengthen our defenses, we've developed a risk assessment engine that monitors and controls network access from both production and corporate environments. This engine provides users with real-time visibility into how their changes impact the overall network, allowing them to make informed decisions about access control before making a change, and blocking high risk changes to prevent them from compromising our security posture.
By sharing our experiences and strategies, we aim to demonstrate that how we can simplify the policy management for cross-platform networks without slowing down developer productivity and still keeping the bad actors away
Tavleen Kaur: Tavleen is a Production Engineer at Meta, part of the Infrastructure Security Engineering Org. Her primary focus is on managing Capirca, a cross platform ACL management service that plays a critical role in safeguarding Meta’s edge, backbone, and corporate networks. Prior to her current role, Tavleen worked with Cisco's network security team as Customer Support Engineer where she developed expertise in securing complex network environments.
Speaker Tavleen Kaur - Meta Platforms Inc
Managing millions of access rules across large network infrastructures is a daunting task. These networks contain devices from multiple vendors, each with different syntax and different system capabilities. At Meta, we've tackled this challenge by designing a pipeline that streamlines access request onboarding while ensuring uninterrupted network access. Our pipeline automates the configuration rendering process, reducing manual efforts and minimizing the risk of errors.
We will be talking about adopting CAPIRCA, a firewall and network security policy management tool, to create vendor-agnostic configs that simplify our network infrastructure. After onboarding Capirca from the open-source world, we’ve made some significant changes to it. This helped us with building various services around Capirca, including a service for users to trace their access, deep inspect user changes and add auditing systems that be run ad-hoc to audit our access rules.
To further strengthen our defenses, we've developed a risk assessment engine that monitors and controls network access from both production and corporate environments. This engine provides users with real-time visibility into how their changes impact the overall network, allowing them to make informed decisions about access control before making a change, and blocking high risk changes to prevent them from compromising our security posture.
By sharing our experiences and strategies, we aim to demonstrate that how we can simplify the policy management for cross-platform networks without slowing down developer productivity and still keeping the bad actors away
Tavleen Kaur: Tavleen is a Production Engineer at Meta, part of the Infrastructure Security Engineering Org. Her primary focus is on managing Capirca, a cross platform ACL management service that plays a critical role in safeguarding Meta’s edge, backbone, and corporate networks. Prior to her current role, Tavleen worked with Cisco's network security team as Customer Support Engineer where she developed expertise in securing complex network environments.
Speaker Tavleen Kaur - Meta Platforms Inc










