- create classes for each class of in/out traffic - use hier_include to add firewall rules to each role