- split networking into interface and firewall modules - define named service ports in one location - remove scattered service-level firewall rules