Specifications
set policy rule
SecureStack C3 Configuration Guide 8-11
set policy rule
UsethiscommandtoassignincominguntaggedframestoaspecificpolicyprofileandtoVLANor
Class‐of‐Serviceclassificationrules.
Syntax
Thiscommandhastwoformsofsyntax—onetocreateanadminrule(forpolicyID0),andthe
othertocreateaclassificationruleandattach ittoapolicyprofile.
set policy rule admin-profile {vlantag data [mask mask] admin-pid profile-index}
[port-string port-string]
set policy rule profile-index {ipproto | ipdestsocket | ipsourcesocket | iptos |
tcpdestport | tcpsourceport | udpdestport | udpsourceport} data [mask mask] [vlan
vlan] [cos cos] | [drop | forward]
Parameters
Thefollowingparametersapplytocreatinganadminrule.
Thefollowingparametersapplytocreatingaclassificationrule.
Note: Classification rules are automatically enabled when created.
admin‐profile SpecifiesthatthisisanadminruleforpolicyID0.
vlantagdata ClassifiesbasedonVLANtagspecifiedbydata.Valueofdatacanrange
from1to4094or0xFFF.
maskmask (Optional)Specifiesthenumberofsignificantbitstomatch,dependent
onthedatavalueentered.Valueof
maskcanrangefrom1to12.
RefertoTable 8‐3forvalidvaluesforeachclassificationtypeanddata
value.
admin‐pid
profile‐index
Associatesthisadminrulewithapolicyprofile,identifiedbyitsindex
number.Policyprofilesareconfiguredwiththesetpolicyprofile
commandasdescribed
in“setpolicyprofile”onpage 8‐4.
Validprofile‐indexvaluesare1‐255.
port‐stringport‐string (Optional)Assignsthisruletothespecifiedpolicyprofileonspecific
ingressport(s).Rulewouldnotbeuseduntilpolicyisassignedtothe
specifiedport(s)usingthesetpolicyportcommand
asdescribedin“set
policyport”onpage 8‐15 .
profile‐index Specifiesapolicyprofilenumbertowhichthisrulewillbeassigned.
Policyprofilesareconfiguredwiththesetpolicyprofilecommandas
describedin“setpolicyprofile”onpage 8‐4.Validprofile‐indexvaluesare
1‐255.
ipproto ClassifiesbasedonProtocolfieldinIPpacket.
ipdestsocket Classifies
basedondestinationIPaddresswithoptionalpost‐fixedport.
ipsourcesocket ClassifiesbasedonsourceIPaddress,withoptionalpost‐fixedport.
iptos ClassifiesbasedonTypeofServicefieldinIPpacket.
tcpdestport ClassifiesbasedonTCPdestinationport.