A method of creating a structured access list template, which includes
dividing an access list template into a plurality of sections, creating
an inbound local rule group for the bubble, creating an outbound local
rule group for the bubble, creating an inbound remote rule group for the
bubble, and creating an outbound remote rule group for the bubble. A
method of creating an access list for each of the plurality of bubble
boundary devices, which includes creating an address table that includes
a plurality of addresses corresponding to devices in a bubble partition,
creating a protocol table that includes a list of network services and
whether each of the network services are granted or denied access to the
bubble partition, creating an access list template using the address
table and the protocol table, generating an access list from the access
list template, and providing the access list to one of the plurality of
bubble boundary devices.