9-15
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter9 Managing Policy E lements
Managing Policy Conditions
Creating, Duplicating, and Editing Device Port Filters
Use the Device Port Filters page to create, duplicate, and edit device port filters. To do this:
Step1 Choose Policy Elements > Session Conditions > Network Conditions > Device Port Filters.
The Device Port Filters page appears with a list of device port filters that you have configured.
Step2 Click Create. You can also:
Check the check box next to the device port filter that you want to duplicate, then click Duplicate.
Check the check box next to the device port filter that you want to edit, then click Edit.
Click Export to save a list of device port filters in a .csv file. For more information, see Exporting
Network Conditions, page 9-9.
Click Replace from File to perform a bulk import of device port filters from a .csv import file. For
more information, see Importing Network Conditions, page9-8.
Step3 Enter the values for the following fields:
Name—Name of the device port filter.
Description—A description of the device port filter.
Step4 Edit the fields in any or all of the following tabs:
IP Address—See Defining IP Address-Based Device Port Filters, page9-15 for a description of the
fields in this tab.
Device Name—See Defining NDG-Based Device Port Filters, page9-17 for a description of the
fields in this tab.
Network Device Group—See Defining NDG-Based Device Port Filters, page9-17 for a description
of the fields in this tab.
Note To configure a filter, at a minimum, you must enter filter criteria in at least one of the three tabs.
Step5 Click Submit to save the changes.
Related Topics
Managing Network Conditions, page 9-6
Importing Network Conditions, page 9-8
Creating, Duplicating, and Editing End Station Filters, page 9-9
Creating, Duplicating, and Editing Device Filters, page 9-12
Defining IP Address-Based Device Port Filters
You can create, duplicate, and edit the IP addresses of the network device ports that you want to permit
or deny access to. To do this:
Step1 From the IP Address tab, do one of the following:
Click Create.