Switch User Manual

clear policy rule
SecureStack C3 Configuration Guide 11-13
ThisexampleshowshowtouseTable 113toassignaruletopolicyprofile1thatwilldropIP
sourcetrafficfromIPaddress1.2.3.4.Ifmask32isnotspecif iedasshown,adefaultmaskof48bits
(IPaddress+port)wouldbeapplied:
C3(su)->set policy rule 1 ipsourcesocket 1.2.3.4 mask 32 drop
clear policy rule
Usethiscommandtodeletepolicyclassificationruleentries.
Syntax
Thiscommandhastwoformsofsyntax—onetoclearan adminrule(forpolicyID0),andtheother
toclearaclassificationrule.
clear policy rule admin-profile {vlantag data [mask mask]
clear policy rule profile-index {all-pid-entries | {ether | ipproto | ipdestsocket
| ipsourcesocket | iptos | macdest | macsource | tcpdestport | tcpsourceport |
udpdestport | udpsourceport}}
Parameters
Thefollowingparametersapplytodeletinganadminrule.
Thefollowingparametersapplytodeletingaclassificationrule.
adminprofile SpecifiesthattheruletobedeletedisanadminruleforpolicyID0.
vlantagdata DeletestherulebasedonVLANtagspecifiedbydata.Valueofdatacan
rangefrom
1to4094or0xFFF.
maskmask (Optional)Specifiesthenumberofsignificantbitstomatch,dependent
onthedatavalueentered.Valueofmaskcanrangefrom1to12.
RefertoTable 113forvalidvaluesforeachclassificationtypeanddata
value.
profileindex Specifiesapolicyprofileforwhichtodeleteclassificationrules.Valid
profileindexvaluesare1‐255.
allpidentries Deletesallentriesassociatedwiththespecifiedpolicyprofile.
ether DeletesassociatedEthernetIIclassificationrule.
ipproto DeletesassociatedIPprotocolclassificationrule.
ipdestsocket DeletesassociatedIPde stinationclassificationrule.
ipsourcesocket Deletesassociated
IPsourceclassificationrule.
iptos DeletesassociatedIPTypeofServiceclassificationrule.
macdest DeletesassociatedMACdestinationaddressclassificationrule.
macsource DeletesassociatedMACsourceaddressclassificationrule.
tcpdestport DeletesassociatedTCPdestinationportclassificationrule.
tcpsourceport DeletesassociatedTCPsourceportclassificationrule.
udpdestport DeletesassociatedUDPdestinationportclassificationrule.
udpsourceport Deletes
associatedUDPsourceportclassificationrule.