Specifications

18-16 VNS Commands (vnsmode)
Usage
EnablingAPcustomfiltersallowsyoutoaccessthevnsmode:defaultpolicy:apfilterscontextby
executingtheapfilterscommand.Thevnsmode:defaultpolicy:apfilterscontextallowsyouto
configureadditionalfiltersfortheAPs.
FilteringontheAPmustbeenabledusingtheulfilterapenablecommandfortheapcustom
commandtobevisiblein
theCLI.Theapcustomenablecommandmakestheapfilterscommand
visible.
Examples
ThefollowingexampleenablesAPcustomfilters:
EWC.enterasys.com:vnsmode:default-policy# ulfilterap enable
EWC.enterasys.com:vnsmode:default-policy# apcustom enable
EWC.enterasys.com:vnsmode:default-policy# apfilters
EWC.enterasys.com:vnsmode:default-policy:apfilters#
18.4.9 apfilters
Usetheapfilterscommandtoenterthevnsmode:defaultpolicy:apfilterscontextforthe
configuringofAPcustomfilters.APcustomfiltersareappliedattheAP.DefaultpolicyAP
customfiltersareappliedwhennoAPcustomfiltersareconfiguredforpolicyappliedattheAP.
Theapfilterscommandisaccessiblefrom
thevnsmode:defaultpolicycontext.
ThiscommandisnotvisibleintheCLIifyouexecutetheapcustomdisablecommand.
Thefollowingcommandsareavailableinthevnsmode:defaultpolicy:apfilterscontext:
create
config
delete
move
18.4.9.1 create
Usethecreatecommandtocreate,insert,orappendanewAPfilterruleforthisdefaultpolicy.
Thecreatecommandisaccessiblefromthevnsmode:defaultpolicy:apfilterscontext.
Ifadvancedfiltermodehasbeenenabledwiththeenableadvancefilteringcommand(page203),
theAdvancedmodesyntaxispresented.If
advancedfiltermodeisnotenabled,theBasicmode
syntaxispresented.
Syntax
Basic mode syntax:
create <pos> proto <protocol> (<ipaddress/mask> | interface-subnet | interface-ip)
[(port <port> [<port>]) | (type <type> [<type>])] in (none|dst) out (none|src)
(allow | deny)
Note: The apfilter command has been replaced by the apfilters command. apfilter is deprecated.