Switch User Manual
set policy rule
SecureStack C3 Configuration Guide 11-11
Defaults
None.
Mode
Switchcommand,read‐write.
profile‐index Specifiesapolicyprofilenumbertowhichthisrulewillbeassigned.
Policyprofilesareconfiguredwiththesetpolicyprofilecommandas
describedin“setpolicyprofile”onpage 11‐4.Validprofile‐indexvalues
are1‐255.
ether Specifiesthattheruleshouldapply
totrafficwiththespecifiedtypefield
inEthernetIIpacket.
ipproto SpecifiesthattheruleshouldapplytotrafficwiththespecifiedProtocol
fieldinIPpacket.
ipdestsocket Specifiesthatthe ruleshouldapplytotrafficwiththespecified
destinationIPaddresswithoptionalpost‐fixedport.
ipsourcesocket Specifiesthattherule
shouldapplytotrafficwiththespecif iedsourceIP
address,withoptionalpost‐fixedport.
iptos SpecifiesthattheruleshouldapplytotrafficwiththespecifiedTypeof
ServicefieldinIPpacket.
macdest Specifiesthattheruleshould applytotrafficwiththespecifiedMAC
destinationaddress.
macsource Specifiesthatthe
ruleshouldapplytotrafficwiththespecifiedMAC
sourceaddress.
tcpdestport SpecifiesthattheruleshouldapplytotrafficwiththespecifiedTCP
destinationport.
tcpsourceport SpecifiesthattheruleshouldapplytotrafficwiththespecifiedTCP
sourceport.
udpdestport Specifiesthattheruleshouldapplytotrafficwiththe
specifiedUDP
destinationport.
udpsourceport SpecifiesthattheruleshouldapplytotrafficwiththespecifiedUDP
sourceport.
data Specifiesthecodeforthespecifiedtrafficclassifier(listedabove).This
valueisdependentonthe classificationtypeentered.RefertoTable 11‐3
forvalidvaluesforeachclassificationtype.
maskmask (Optional)
Specifiesthenumberofsignificantbitstomatch,dependenton
thedatavalueentered.RefertoTable 11‐3forvalidvaluesforeach
classificationtypeanddatavalue.
vlanvlan SpecifiestheactionoftheruleistoclassifytoaVLANID.
coscos Specifiestheactionoftheruleis
toclassifytoaClass‐of‐ServiceID.Valid
valuesare0‐4095. Avalueof‐1indicatesthatnoCoSforwarding
behaviormodificationisdesired.(NotsupportedonB3,C3,andG3.)
drop|forward Specifiesthatpacketswithinthisclassificationwillbedroppedor
forwarded.