Specifications
Policy Overview
May 18, 2009 Page 4 of 32
networkaccess andresourceusagealignwiththesecurityrequirements,networkcapabilities,and
legitimateuserneedsasdefinedbythenetworkadministra tor.
The Policy Role
Arole,suchassales,admin,orengineering,isfirstidentifiedanddefinedintheabstractasthe
basisforconfiguringapolicyrole.Oncearoleisdefined,apolicyroleisconfiguredandappliedto
theappropriatecontextusingasetofrulesthatcancontrolandprioritizevarious
typesofnetwork
traffic.Therulesthatmakeupapolicyrolecontainbothclassificationdefinitionsandactionstobe
enforcedwhenaclassificationismatched.ClassificationsincludeLayer2,Layer3,andLayer4
packetfields.PolicyactionsthatcanbeenforcedincludeVLANassignment,filtering,inbound
ratelimiting,
outboundrateshaping,priorityclassmappingandlogging.
Policy Roles
Defining a Policy Role
Thepolicyroleisacontainerthatholdsallaspectsofpolicyconfigurationforaspecificrole.Policy
rolesareidentifiedbyanumericprofile‐indexvaluebetween1andthemaximumnumberofroles
supportedontheplatform.Pleaseseeyourdevice’sfirmwarereleasenotesforthemaximum
numberof
rolessupported.Policyrolesareconfiguredusingthesetpolicyprofilecommand.
Policyconfigurationiseitherdirectlyspecifiedwiththesetpolicyprofilecommandoris
associatedwiththerolebyspecifyingtheprofile‐indexvaluewithinthecommandsyntaxwhere
thegivenpolicyoptionisconfigured.Forexample,when
configuringapolicymaptableentry
usingthesetpolicymaptablecommand(seeVLAN‐to‐PolicyMappingonpage 5),thecommand
syntaxrequiresthatyouidentifythepolicyrolethemaptableentrywillbeassociatedwith,by
specifyingtheprofile‐index value.
Whenmodifyinganexistingpolicyrolethedefaultbehavioris
toreplacetheexistingrolewiththe
newpolicyroleconfiguration.Usetheappendoptiontolimitthechangetotheexistingpolicy
roletotheoptionsspecifiedintheenteredcommand.
Apolicyrolecanalso beidentifiedbyatextnameofbetween1and64characters.Thisname
value
isusedbytheRADIUSfilter‐IDattributetoidentifythepolicyroletobeapplied bytheswitch
withasuccessfulauthentication.
Setting a Default VLAN for this Role
AdefaultVLANcanbeconfiguredforapolicyrole.AdefaultVLANwillonlybeusedwhen
eitheraVLANisnotspecificallyassignedbyaclassificationruleorallpolicyroleclassification
rulesaremissed.ToconfigureadefaultVLAN,enablepvid‐statusandspecifytheportVLANto
beused.pvid‐statusisdisabledbydefault.
Note: Enterasys supports the assignment of port VLAN-IDs 1 - 4094 (4093 on the SecureStack
switch). VLAN-IDs 0 and 4095 can not be assigned as port VLAN-IDs, but do have special
meanings within a policy context and can be assigned to the pvid parameter (See the Configuring
VLANs feature guide at http://secure.enterasys.com/support/manuals/ for further information on
these two VLAN-IDs. Within a policy context:
• 0 - Specifies an explicit deny all
• 4095 - Specifies an explicit permit all