In order to remove security vulnerability in an IP-SAN and eliminate
unauthorized access by spoofing, firewalls are installed in valid user
servers and storage devices, and a distributed firewall manager for
managing the firewalls integrally is provided in the IP-SAN. The
distributed firewall manager obtains discovery domain information from an
iSNS server, determines nodes registered in the iSNS server as the nodes
of valid users, and autocreates a security policy according to sets
consisting of an iSCSI name and portal information. This security policy
is distributed to all of the firewalls as a common policy, whereupon
access control is executed to deny TCP connection requests from
unauthorized access sources.