Enterasys Networks 9034313-07 manual Set policy rule, Admin‐profile, Vlantag data

Models: 9034313-07

1 872
Download 872 pages 24.54 Kb
Page 360
Image 360

set policy rule

Ether II packet type

X

X

X X

LLC DSAP/SSAP/CTRL

VLAN tag

Replace tci

Port string

X X X

X

X X

=============================================================

set policy rule

Use this command to assign incoming untagged frames to a specific policy profile and to VLAN or Class‐of‐Service classification rules.

Note: Refer to Appendix A, Policy and Authentication Capacities for information about limits on certain rule types for this platform.

Syntax

This command has two forms of syntax—one to create an admin rule, and the other to create a traffic classification rule and attach it to a policy profile.

set policy rule admin-profile {vlantag data [mask mask] admin-pid profile-index}[port-string port-string]

set policy rule profile-index{ether ipproto ipdestsocket ipsourcesocket iptos macdest macsource tcpdestport tcpsourceport udpdestport udpsourceport} data [mask mask] {[vlan vlan] [cos cos] [drop forward]}

Note: Classification rules are automatically enabled when created.

Parameters

The following parameters apply to creating an admin rule. See the Usage section below for more information about admin rules.

admin‐profile

Specifies that this is an admin rule.

vlantag data

Classifies based on VLAN tag specified by data. Value of data can range

 

from 1 to 4094 or 0xFFF.

 

 

mask mask

(Optional) Specifies the number of significant bits to match, dependent

 

on the data value entered. Value of mask can range from 1 to 12.

 

Refer to Table 11‐3 for valid values for each classification type and data

 

value.

 

 

admin‐pid

Associates this admin rule with a policy profile, identified by its index

profile‐index

number. Policy profiles are configured with the set policy profile

 

command as described in set policy profile” on page 11‐4.

Valid profile‐index values are 1255.

port‐string port‐string (Optional) Assigns this rule with the specified policy profile on specific ingress port(s). Rule would not be used until policy is assigned to the specified port(s) using the set policy port command as described in set policy port” on page 11‐15.

The following parameters apply to creating a traffic classification rule.

11-10 Policy Classification Configuration

Page 360
Image 360
Enterasys Networks 9034313-07 manual Set policy rule, Admin‐profile, Vlantag data