Specifications

Security Options 67
Chapter 5
FIGURE 5-5 Rule Ordering
CLI Configuration
All CLI configuration for traffic/firewall policies is done under the ip
access-list session command. Equivalent CLI configuration for the example
shown above is:
ip access-list session Internet_Only
user alias Internal_Network svc-dhcp permit
user alias Internal_Network svc-dns permit
user alias Internal_Network any deny
user any svc-http permit
user any svc-https permit
user any svc-ike permit
user any any deny
Applying Traffic Policies to Physical Ports
Traffic policies can be applied either to user roles, as described below in the
User Roles section, or to physical ports. To apply traffic policies to a physical
port, navigate to Configuration > Switch > Port. Select the port to which the
policy should be applied, then select the policy under
Firewall Policy as shown
in the figure below.