Specifications

set policy rule
SecureStack C3 Configuration Guide 8-11
set policy rule
UsethiscommandtoassignincominguntaggedframestoaspecificpolicyprofileandtoVLANor
ClassofServiceclassificationrules.
Syntax
Thiscommandhastwoformsofsyntax—onetocreateanadminrule(forpolicyID0),andthe
othertocreateaclassificationruleandattach ittoapolicyprofile.
set policy rule admin-profile {vlantag data [mask mask] admin-pid profile-index}
[port-string port-string]
set policy rule profile-index {ipproto | ipdestsocket | ipsourcesocket | iptos |
tcpdestport | tcpsourceport | udpdestport | udpsourceport} data [mask mask] [vlan
vlan] [cos cos] | [drop | forward]
Parameters
Thefollowingparametersapplytocreatinganadminrule.
Thefollowingparametersapplytocreatingaclassificationrule.
Note: Classification rules are automatically enabled when created.
adminprofile SpecifiesthatthisisanadminruleforpolicyID0.
vlantagdata ClassifiesbasedonVLANtagspecifiedbydata.Valueofdatacanrange
from1to4094or0xFFF.
maskmask (Optional)Specifiesthenumberofsignificantbitstomatch,dependent
onthedatavalueentered.Valueof
maskcanrangefrom1to12.
RefertoTable 83forvalidvaluesforeachclassificationtypeanddata
value.
adminpid
profileindex
Associatesthisadminrulewithapolicyprofile,identifiedbyitsindex
number.Policyprofilesareconfiguredwiththesetpolicyprofile
commandasdescribed
insetpolicyprofileonpage 84.
Validprofileindexvaluesare1‐255.
portstringportstring (Optional)Assignsthisruletothespecifiedpolicyprofileonspecific
ingressport(s).Rulewouldnotbeuseduntilpolicyisassignedtothe
specifiedport(s)usingthesetpolicyportcommand
asdescribedinset
policyportonpage 815 .
profileindex Specifiesapolicyprofilenumbertowhichthisrulewillbeassigned.
Policyprofilesareconfiguredwiththesetpolicyprofilecommandas
describedinsetpolicyprofileonpage 84.Validprofileindexvaluesare
1‐255.
ipproto ClassifiesbasedonProtocolfieldinIPpacket.
ipdestsocket Classifies
basedondestinationIPaddresswithoptionalpostfixedport.
ipsourcesocket ClassifiesbasedonsourceIPaddress,withoptionalpostfixedport.
iptos ClassifiesbasedonTypeofServicefieldinIPpacket.
tcpdestport ClassifiesbasedonTCPdestinationport.